Impact
The flaw resides in the Oracle Internet Directory LDAP Server and allows an unauthenticated attacker with network access to the LDAP port to bypass authentication and perform arbitrary operations. This results in total loss of confidentiality, integrity and availability of the directory service, effectively enabling a full takeover of Oracle Internet Directory. The vulnerability is indexed as CWE‑287 (Improper Authentication) and CWE‑306 (Missing Authentication for Critical Function).
Affected Systems
Oracle Internet Directory versions 12.2.1.4.0 and 14.1.2.1.0 are affected. The problem exists in the OID LDAP Server component of Oracle Fusion Middleware and applies to all installations exposing this service.
Risk and Exploitability
The CVSS base score is 9.8, indicating a severe vulnerability with a high likelihood of successful exploitation. The EPSS score is less than 1% and the vulnerability is not yet listed in the CISA KEV catalog, suggesting that widespread exploitation is currently unlikely. However, the attack vector is purely network-based; any host that can reach the exposed LDAP endpoint can authenticate without credentials, execute arbitrary actions and achieve full control of the directory. The risk is high for systems that expose the LDAP service to untrusted networks and low for tightly isolated or firewall‑protected deployments.
OpenCVE Enrichment