Impact
The Oracle Internet Directory LDAP Server contains an authentication bypass that allows an unauthenticated attacker with network access to gain administrative control. Based on the description, it is inferred that the attacker can authenticate as an administrator, providing the ability to read, modify, or delete directory entries. Successful exploitation would give full command over the directory, potentially compromising any systems that rely on it for authentication and authorization.
Affected Systems
Oracle Internet Directory, version 12.2.1.4.0 and 14.1.2.1.0, produced by Oracle Corporation.
Risk and Exploitability
The CVSS v3.1 base score of 10.0 signals a critical threat level. The EPSS score of less than 1% indicates a low probability of exploitation at present, but the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The likely attack vector is direct LDAP network access; any host with such access could attempt the exploit. Because the flaw bypasses authentication entirely, successful exploitation would grant full administrative rights to the directory, exposing confidential data, enabling undetected tampering, and potentially causing service outages.
OpenCVE Enrichment