Impact
The vulnerability resides in the Virtual Directory Server of Oracle Fusion Middleware. It allows an attacker with limited privileges and network access through LDAP to compromise the directory instance. Successful exploitation results in takeover, granting the attacker full control over the affected Virtual Directory, thereby exposing confidentiality, integrity, and availability of all data served by that component.
Affected Systems
Oracle Virtual Directory versions 12.2.1.4.0 and 14.1.2.0.0 are affected. Users running these releases should ascertain which product tier they are using and locate the matching Oracle patch for that version.
Risk and Exploitability
The CVSS 3.1 Base Score of 8.8 signals high severity with full confidentiality, integrity, and availability impacts. The EPSS score is < 1%, indicating a very low yet non‑zero probability of exploitation, and the issue is not listed in the CISA KeV catalog. The likely attack path involves an adversary exposing an LDAP interface, then leveraging the low privilege user context to execute privileged operations. The vulnerability is easily exploitable, making the risk for exposed installations significant.
OpenCVE Enrichment