Impact
This vulnerability in Oracle Unified Directory allows an unauthenticated attacker with network access over LDAP to gain unauthorized access to critical data or all accessible directory data. The weakness enables an attacker to bypass authentication controls and read protected information, leading to a high confidentiality impact as noted by the CVSS 7.5 score.
Affected Systems
Affected products include Oracle Corporation’s Oracle Unified Directory, specifically versions 12.2.1.4.0 and 14.1.2.1.0. No additional vendor or product versions are listed as impacted.
Risk and Exploitability
The CVSS base score of 7.5 indicates a serious confidentiality concern, yet the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, suggesting a lower current exploitation likelihood. The attack vector is defined as network-based via LDAP, with no authentication required on the part of the attacker. Successful exploitation would allow the attacker to retrieve directory data that should otherwise be restricted.
OpenCVE Enrichment