Impact
The vulnerability allows an unauthenticated attacker who can reach the Oracle Unified Directory service over LDAP to bypass authentication controls and gain full read access to the directory’s data. This breach could expose sensitive identity information and configuration data, potentially allowing the attacker to pivot further into the network. The weakness is an authentication bypass, documented as CWE-287.
Affected Systems
Oracle Unified Directory versions 12.2.1.4.0 and 14.1.2.1.0 are affected. The issue is present in the OUD Core component of Oracle Fusion Middleware and requires no credentials to exploit.
Risk and Exploitability
The CVSS 3.1 base score of 7.5 reflects a high confidentiality impact. Attack can be carried out over LDAP traffic from the network without authentication, making it highly accessible to attackers with network reach. EPSS is not available, but the vulnerability is not listed in CISA’s KEV catalog, suggesting current exploitation reports are unknown. Nonetheless, the potential for widespread data compromise warrants immediate remediation.
OpenCVE Enrichment