Impact
The vulnerability, a CWE‑284 access control flaw in Oracle Unified Directory (OUD Core), allows a high‑privileged attacker with LDAP network access to create, delete or modify critical data and to cause the directory service to hang or crash repeatedly. This results in significant loss of data integrity and a complete denial of service, potentially affecting any Fusion Middleware components that depend on OUD.
Affected Systems
Oracle Unified Directory versions 12.2.1.4.0 and 14.1.2.1.0 are affected. Additional Oracle Fusion Middleware components that rely on OUD may also experience elevated risk.
Risk and Exploitability
The CVSS v3.1 base score of 8.7 indicates a severe impact to integrity and availability, and the scope change increases the reach of the vulnerability. Despite an EPSS score of less than 1% and the vulnerability not being listed in the CISA KEV catalog, the network‑based attack vector via LDAP and requirement for high privileges make it a notable threat for exposed directories.
OpenCVE Enrichment