Impact
Oracle Internet Directory is vulnerable in versions 12.2.1.4.0 and 14.1.2.1.0 to a flaw that allows an attacker with low privileges and network access via LDAP to compromise the server. The flaw can lead to full takeover of the directory service, resulting in loss of confidentiality, integrity, and availability. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, with a base score of 9.9.
Affected Systems
Affected products are Oracle Internet Directory from Oracle Corporation. The specific versions impacted are 12.2.1.4.0 and 14.1.2.1.0. These versions are part of Oracle Fusion Middleware and may be deployed in enterprise directory services.
Risk and Exploitability
The vulnerability carries a very high severity score of 9.9, indicating a significant threat to confidentiality, integrity, and availability. The EPSS score of less than 1% suggests that exploitation is unlikely to be widespread at the present time, and the issue is not listed in the CISA KEV catalog. The likely attack vector is a network-based LDAP request from a low-privileged client; the attacker must have network reach to the LDAP service. If the flaw is exploited, the attacker could gain full control over the directory, possibly impacting other products that rely on it. The combination of a low exploitation barrier and a large attack surface warrants immediate attention and remediation.
OpenCVE Enrichment