Impact
A vulnerability in Oracle Unified Directory permits a low‑privileged attacker with LDAP network access to create, delete, or modify critical data without proper authorization. This flaw can lead to unauthorized changes to directory entries, compromising confidentiality and integrity of stored information.
Affected Systems
Oracle Unified Directory versions 12.2.1.4.0 and 14.1.2.1.0 are vulnerable.
Risk and Exploitability
The CVSS 3.1 score of 6.8 signals moderate severity with high confidentiality and integrity impacts. Exploitation requires LDAP connectivity and a low‑privilege account; the weakness is described as difficult to exploit. The EPSS score is < 1%, indicating a very low expected exploitation probability, and it is not listed in CISA KEV. Nevertheless, an attacker who can reach the LDAP interface could gain unauthorized access to all directory data and alter it at will.
OpenCVE Enrichment