Impact
The Oracle Internet Directory (OID) LDAP Server contains an easily exploitable flaw that permits an attacker with only low‑privilege credentials and network connectivity to LDAP traffic to fully compromise the directory service. The vulnerability enables the attacker to bypass normal access controls and assume administrative control, resulting in complete confidentiality, integrity and availability compromise of the OID instance. The flaw is characterized by the CVSS vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H and carries a 9.9 base score. This flaw aligns with CWE-284: Improper Access Control.
Affected Systems
Affected Oracle products are Oracle Internet Directory 12.2.1.4.0 and 14.1.2.1.0. These releases are part of Oracle Fusion Middleware and are used for authentication and directory services in many enterprise environments. The advisory lists both versions as vulnerable; no other versions are affected according to the current data.
Risk and Exploitability
The CVSS 9.9 score reflects high severity, and the EPSS value indicates that the exploit probability is very low at present; however, the vulnerability can be leveraged remotely over LDAP without authentication, and the scope change makes it possible to affect other components. The advisory does not list this issue in the CISA KEV catalog, but the lack of exploitation data does not reduce the risk, especially for organizations that expose LDAP services externally. Attackers can achieve full system ingress by simply sending crafted LDAP requests over the network, and the low privilege requirement lowers the bar for initial compromise.
OpenCVE Enrichment