Impact
The Oracle Internet Directory (OID) LDAP Server contains an access control flaw that allows an attacker with low-privilege credentials who can reach the LDAP service to fully compromise the directory. As the vulnerability’s CVSS vector indicates AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, it impacts confidentiality, integrity and availability. Attackers could bypass normal authorization checks and gain administrative control, potentially allowing takeover of the OID instance and, due to the scope change, affecting other components within the Oracle Fusion Middleware stack. The weakness aligns with CWE‑284: Improper Access Control.
Affected Systems
The affected product variants are Oracle Internet Directory 12.2.1.4.0 and 14.1.2.1.0. These releases are part of Oracle Fusion Middleware and provide authentication and directory services across many enterprises. The advisory specifies only these two versions as vulnerable, and no other releases are mentioned.
Risk and Exploitability
The base CVSS score of 9.9 marks the vulnerability as critical, while the EPSS score of < 1% indicates the current exploitation probability is very low. The issue is not listed in the CISA KEV catalog. Although the description does not state the attack can occur without authentication, it is clear that an attacker must have network connectivity to the LDAP interface and possess at least low‑privilege credentials; this inference is based on the phrase “low privileged attacker with network access via LDAP.” If the LDAP service is reachable from the internet or from less trusted networks, the risk of initial compromise increases. Organizations should evaluate their LDAP exposure and apply the vendor’s fix promptly.
OpenCVE Enrichment