Impact
A flaw in Oracle Internet Directory’s LDAP server causes improper input validation, allowing a low‑privileged attacker with network access to send crafted LDAP requests that lead to a full takeover of the directory service. The compromise affects confidentiality, integrity, and availability of the directory, and could give the attacker extensive control over the service. Oracle Internet Directory versions 12.2.1.4.0 and 14.1.2.1.0 are affected, as referenced in the Oracle Security Alert and listed in the CPE entries.
Affected Systems
Oracle Internet Directory versions 12.2.1.4.0 and 14.1.2.1.0 are impacted. These versions are part of Oracle Fusion Middleware’s Identity Services.
Risk and Exploitability
The CVSS 3.1 base score of 9.9 marks the flaw as critical, while the EPSS score of < 1% indicates a very low current exploitation probability. The vulnerability is not in the CISA KEV catalog. Attackers need network reach to the LDAP port; the description does not state that authentication is required, so an attacker who can reach the directory service may exploit the flaw. The scope change noted in the description suggests that additional Oracle products could also be impacted.
OpenCVE Enrichment