Impact
An unauthenticated LDAP connection to Oracle Unified Directory can trigger a system hang or a complete crash, resulting in a denial‑of‑service condition. The vulnerability entails no compromise of confidential data or user integrity, but it fully disrupts the availability of the directory service for any client that relies on it. Because the attack requires only network reachability and no credentials, an attacker can repeatedly invoke the faulty behavior until the service becomes unavailable.
Affected Systems
Oracle Unified Directory versions 12.2.1.4.0 and 14.1.2.1.0 are affected. These releases are part of Oracle Fusion Middleware and provide LDAP directory services to internal and external applications.
Risk and Exploitability
The CVSS 3.1 base score of 7.5 signals a substantial availability impact. EPSS indicates a very low probability of exploitation (< 1%); however, the vulnerability is not listed in CISA’s KEV catalog, so no publicly documented exploit is known. The attack vector is inferred to be network‑based LDAP traffic, requiring no authentication, which means any host able to reach the LDAP port could potentially force the directory to crash, leading to outages for connected systems.
OpenCVE Enrichment