Impact
A flaw in the LDAP Server component of Oracle Internet Directory allows a low‑privileged attacker with network access to the LDAP service to compromise the directory. Successful exploitation results in complete control of the directory, leading to loss of confidentiality, integrity, and availability for data stored there and potentially for other Oracle Fusion Middleware products that rely on it.
Affected Systems
Oracle Corporation’s Internet Directory, versions 12.2.1.4.0 and 14.1.2.1.0, are affected by this vulnerability through the LDAP Server component.
Risk and Exploitability
The CVSS 3.1 score of 9.9 indicates critical severity. The EPSS score is 0.00352 (less than 1%), and the vulnerability is not listed in the CISA KEV catalog. The attack vector is network‑based via LDAP and only requires low privilege, making the vulnerability easily exploitable. The scope change means that successful compromise of the directory could also impact other systems that consume the directory services.
OpenCVE Enrichment