Impact
This vulnerability in Oracle Unified Directory allows an unauthenticated attacker with network access over LDAP to bypass authentication controls and read directory data that should otherwise be restricted. The weakness is a direct privilege escalation flaw that leads to a high confidentiality impact, reflected in the CVSS 7.5 score.
Affected Systems
Affected products include Oracle Corporation’s Oracle Unified Directory, specifically versions 12.2.1.4.0 and 14.1.2.1.0. No other vendors or product versions are listed as impacted.
Risk and Exploitability
The CVSS Base Score of 7.5 indicates a serious confidentiality concern; the EPSS score of 0.00398 (< 1%) indicates a very low exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is network-based via LDAP. If exploited, an attacker can retrieve directory data across the entire accessible scope without authentication.
OpenCVE Enrichment