Impact
The vulnerability is in the Oracle Internet Directory LDAP Server. An attacker who has low privileges and network access to the LDAP interface can exploit a flaw that allows escalation to full control over the directory service. The CVSS 3.1 base score of 9.9 affects confidentiality, integrity, and availability. The nature of the weakness is consistent with an improper access control or privilege escalation vulnerability.
Affected Systems
Oracle Corporation’s Oracle Internet Directory is affected. The vulnerable versions are 12.2.1.4.0 and 14.1.2.1.0. Attackers can potentially impact other Oracle products because the exploitation may change the scope of the compromise.
Risk and Exploitability
The CVSS score of 9.9 indicates critical impact, but the EPSS score is less than 1 percent, suggesting that the likelihood of exploitation at this time is extremely low. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is over the network via LDAP with a low privilege requirement, meaning that any host with network connectivity to the LDAP service and minimal local user rights can mount an attack, potentially resulting in a takeover of the Oracle Internet Directory and cascading effects on dependent systems.
OpenCVE Enrichment