Impact
This vulnerability allows a low‑privileged attacker with network access to the LDAP service of Oracle Unified Directory to compromise the entire directory service, leading to a full takeover. The flaw is easily exploitable and results in complete loss of confidentiality, integrity, and availability for the affected system.
Affected Systems
Oracle Corporation’s Oracle Unified Directory product, specifically versions 12.2.1.4.0 and 14.1.2.1.0.
Risk and Exploitability
The CVSS base score of 8.8 highlights severe impact on confidentiality, integrity, and availability. The EPSS score of less than 1% indicates a low probability of public exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need only low privilege and network access via LDAP, with no user interaction required. Once exploited, the attacker can take full control of the Oracle Unified Directory instance.
OpenCVE Enrichment