Impact
The flaw resides in the Oracle Internet Directory LDAP Server component and is rated CVSS 3.1 9.8, indicating total loss of confidentiality, integrity and availability. Attackers with network reach to an exposed LDAP endpoint can authenticate without credentials and execute arbitrary operations that grant complete control of the directory service. This ability to bootstrap authentication allows an attacker to manipulate directory entries and ultimately take over the directory service entirely.
Affected Systems
Oracle Internet Directory versions 12.2.1.4.0 and 14.1.2.1.0 are affected. The vulnerability is specific to the OID LDAP Server within the Oracle Fusion Middleware stack.
Risk and Exploitability
Although the EPSS score is less than 1% and the vulnerability is not yet listed in CISA’s KEV catalog, the high CVSS base score and the description of “easily exploitable” indicate that an anonymous user who can reach the LDAP port on the target could readily use it. The attack vector is network-based; any host able to send LDAP traffic to the vulnerable service is a potential entry point. The risk is therefore high if the service is exposed to untrusted networks, but the probability of widespread exploitation remains low at the time of this analysis.
OpenCVE Enrichment