Impact
Oracle Unified Directory suffers a broken access control flaw that allows a low‑privileged attacker with network LDAP access to create, delete, or modify directory entries without proper authorization. The result is unauthorized changes to critical data or full loss of all data stored in the directory, compromising confidentiality and integrity for the affected system.
Affected Systems
Oracle Unified Directory versions 12.2.1.4.0 and 14.1.2.1.0 are impacted by this vulnerability.
Risk and Exploitability
The CVSS 3.1 base score of 8.1 indicates high severity. With an EPSS score of less than 1% and no listing in the CISA KEV catalog, exploitation is considered unlikely at present. However, because the exploit requires only a low‑privileged LDAP client on a reachable network interface, the barrier to attack remains low and an adversary could gain unauthorized full access to directory data using simple LDAP commands.
OpenCVE Enrichment