Impact
This vulnerability in Oracle Internet Directory’s LDAP server permits an unauthenticated attacker with network access to bypass authentication controls and fully compromise the service. Successful exploitation gives the attacker complete control over the directory server, leading to loss of confidentiality, integrity, and availability of all directory data.
Affected Systems
Oracle Internet Directory versions 12.2.1.4.0 and 14.1.2.1.0 are affected.
Risk and Exploitability
The CVSS v3.1 score of 10.0 signals a critical level of severity. The EPSS score is less than 1%, indicating a very low exploitation probability, yet the lack of a restriction on authentication allows the attack to be launched remotely from any network entry point that can reach the LDAP port. The high exploitation potential and the scope change that can impact additional Oracle products further raise the overall risk to systems that rely on these directory services. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment