Description
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Unified Directory. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated LDAP connection to Oracle Unified Directory can trigger a system hang or a complete crash, resulting in a denial‑of‑service condition. The vulnerability entails no compromise of confidential data or user integrity, but it fully disrupts the availability of the directory service for any client that relies on it. Because the attack requires only network reachability and no credentials, an attacker can repeatedly invoke the faulty behavior until the service becomes unavailable.

Affected Systems

Oracle Unified Directory versions 12.2.1.4.0 and 14.1.2.1.0 are affected. These releases are part of Oracle Fusion Middleware and provide LDAP directory services to internal and external applications.

Risk and Exploitability

The CVSS 3.1 base score of 7.5 signals a substantial availability impact. EPSS indicates a very low probability of exploitation (< 1%); however, the vulnerability is not listed in CISA’s KEV catalog, so no publicly documented exploit is known. The attack vector is inferred to be network‑based LDAP traffic, requiring no authentication, which means any host able to reach the LDAP port could potentially force the directory to crash, leading to outages for connected systems.

Generated by OpenCVE AI on August 4, 2026 at 03:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Unified Directory patch released in the July 2026 CPU that addresses the denial‑of‑service issue
  • Restrict access to the LDAP port to trusted IP addresses or ranges until the patch is applied
  • After patching, restart the Oracle Unified Directory service to clear any residual failures

Generated by OpenCVE AI on August 4, 2026 at 03:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
Title Oracle Unified Directory LDAP Denial of Service Vulnerability

Tue, 28 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated LDAP Denial of Service in Oracle Unified Directory
Weaknesses CWE-770

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated LDAP Denial of Service in Oracle Unified Directory
Weaknesses CWE-770

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Unified Directory. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
First Time appeared Oracle
Oracle unified Directory
CPEs cpe:2.3:a:oracle:unified_directory:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:unified_directory:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle unified Directory
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Oracle Unified Directory
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T14:09:49.727Z

Reserved: 2026-07-08T15:51:40.536Z

Link: CVE-2026-60436

cve-icon Vulnrichment

Updated: 2026-07-24T14:09:40.193Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:00:03Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption