Impact
The flaw resides in the Oracle Unified Directory component of Oracle Fusion Middleware, allowing an attacker who already possesses high‑privilege credentials and can reach the system via LDAP to take full control of the directory service. The vulnerability can be exploited easily and results in loss of confidentiality, integrity and availability of the directory, potentially affecting any applications that rely on it. The weakness is reflected in the identified CWEs, which indicate improper and missing authorization checks.
Affected Systems
Oracle Unified Directory versions 12.2.1.4.0 and 14.1.2.1.0 are listed as affected. These releases have been confirmed to contain the vulnerability and have been documented as vulnerable in Oracle’s security advisories.
Risk and Exploitability
The CVSS v3.1 base score of 7.2 denotes a high‑impact issue, yet the EPSS score is reported as less than 1 %, indicating a low current exploitation probability. The vulnerability is not included in the CISA KEV catalog. The attacker must be able to reach the LDAP service and possess high‑privilege credentials within the target network; no public remote launch method is described. Based on typical enterprise environments, internal LDAP traffic is commonly available, which could lend the vulnerability an additional feasible attack vector for insiders. However, this statement is inferred from general network practices and is not explicitly stated in the vendor’s description.
OpenCVE Enrichment