Impact
The Oracle Unified Directory product contains a flaw in its OUD Core component that allows an attacker with low privilege and simple network connectivity to the LDAP service to fully compromise the directory. A successful exploit could result in the attacker gaining complete control over the directory, leading to loss of confidentiality, integrity, and availability for the affected system and potentially other applications that rely on it.
Affected Systems
Oracle Unified Directory versions 12.2.1.4.0 and 14.1.2.1.0, part of Oracle Fusion Middleware, are affected. The vulnerability is specific to the OUD Core component of these versions.
Risk and Exploitability
The EPSS score of less than 1 % suggests a low probability of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. However, the CVSS 3.1 base score of 8.5 indicates a high severity. The flaw can be leveraged remotely over LDAP by an attacker who has low privileges and no user interaction, allowing complete takeover of the directory once exploited.
OpenCVE Enrichment