Impact
A vulnerability in Oracle Unified Directory permits a low‑privileged attacker with LDAP network access to create, delete, or modify critical data without proper authorization. This flaw can lead to unauthorized changes to directory entries, compromising confidentiality and integrity of stored information.
Affected Systems
Oracle Unified Directory versions 12.2.1.4.0 and 14.1.2.1.0 are vulnerable.
Risk and Exploitability
The CVSS 3.1 score of 6.8 signals moderate severity with high confidentiality and integrity impacts. Exploitation requires LDAP connectivity and a low‑privilege account; the weakness is described as difficult to exploit. The flaw is not listed in CISA’s KEV catalog and no EPSS score is available, indicating no distributed exploit data yet. Nevertheless, an attacker who can reach the LDAP interface could gain unauthorized access to all directory data and alter it at will.
OpenCVE Enrichment