Impact
This vulnerability allows an unauthenticated attacker with network access via LDAP to take full control of Oracle Internet Directory. The weakness originates from improper authentication enforcement (CWE-287) and the lack of authentication required (CWE-306), enabling remote code execution and complete compromise of the directory service.
Affected Systems
Oracle Internet Directory versions 12.2.1.4.0 and 14.1.2.1.0 are affected. These versions are part of Oracle Fusion Middleware and are deployed in environments where LDAP is exposed over the network.
Risk and Exploitability
The CVSS 3.1 base score of 9.8 indicates a severe impact on confidentiality, integrity, and availability. The EPSS score of less than 1% suggests current exploitation probability is very low, and the vulnerability is not yet listed in the CISA KEV catalog. Nevertheless, the attack vector is network-based via LDAP, requiring no authentication, and success results in total takeover of the directory service.
OpenCVE Enrichment