Impact
The vulnerability in Oracle Unified Directory allows an attacker with low privileges and network access via LDAP to compromise the directory service. The flaw can be exploited relatively easily, enabling the attacker to obtain unauthorized access to critical data and, in some scenarios, full data sets. This vulnerability has a CVSS 3.1 base score of 7.7, with high confidentiality impact and a scope change indicating potential privilege escalation or cross‑component access.
Affected Systems
The affected product is Oracle Unified Directory from Oracle Corporation, specifically versions 12.2.1.4.0 and 14.1.2.1.0. These versions are part of Oracle Fusion Middleware and are used to provide LDAP and directory services primarily for authentication and authorization within corporate environments.
Risk and Exploitability
The exploit requires network connectivity to the LDAP port and no special pre‑existing access rights. While the EPSS score is less than 1%, the CVSS 7.7 rating and the scope change suggest a moderate‑to‑high risk for organizations that expose the UOD service to untrusted networks. The vulnerability is not currently listed on CISA’s KEV catalog. Attackers could leverage the issue to read sensitive directory entries, potentially enabling further attacks such as credential harvesting or account takeover.
OpenCVE Enrichment