Impact
Vulnerability in Oracle Internet Directory allows an attacker with network access to LDAP to authenticate without credentials and gain full control of the directory service. The flaw results in a complete takeover, compromising confidentiality, integrity, and availability of the directory data and services. The impact is equivalent to a remote code execution scenario where the attacker can modify or delete any entry and perform privileged actions within the directory.
Affected Systems
Oracle Internet Directory versions 12.2.1.4.0 and 14.1.2.1.0 are affected. The vulnerability exists in the OID LDAP Server component of Oracle Fusion Middleware.
Risk and Exploitability
The CVSS Base Score is 9.8, indicating a critical severity. An EPSS score of < 1% is available, so while the exploit probability is very low but nonzero, the high CVSS suggests a readily exploitable flaw. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is over the network via LDAP, where an unauthenticated attacker can immediately exploit the defect to compromise the target.
OpenCVE Enrichment