Impact
The Oracle Internet Directory LDAP Server contains an authentication bypass that allows an unauthenticated attacker who can reach the LDAP service over the network to gain full administrative control of the directory. Successful exploitation could enable an attacker to read, modify, or delete directory entries and potentially leverage the compromised directory to impact other applications that rely on it for authentication and authorization, thereby threatening confidentiality, integrity, and availability.
Affected Systems
Oracle Internet Directory, version 12.2.1.4.0 and 14.1.2.1.0, supplied by Oracle Corporation.
Risk and Exploitability
The CVSS v3.1 base score of 10.0 denotes a critical risk level. The EPSS score of less than 1% indicates a low current probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is direct LDAP network access; an attacker with such access can conduct the exploit without prior authentication, potentially affecting any system connected to a vulnerable directory instance. Because the flaw bypasses authentication entirely, successful attacks would grant full administrative rights, exposing sensitive data, allowing undetected tampering, and possibly causing service disruptions.
OpenCVE Enrichment