Impact
An unauthenticated attacker can exploit a flaw in the Oracle Internet Directory LDAP server when given network access to an LDAP port. The flaw allows the attacker to obtain full control of the directory service. Based on the description, it is inferred that the attacker could obtain all configuration data and user information, and potentially use the compromised service for lateral movement. This results in total compromise, affecting confidentiality, integrity and availability, as reflected by the 9.8 CVSS score.
Affected Systems
Oracle Internet Directory, part of Oracle Fusion Middleware, is affected for versions 12.2.1.4.0 and 14.1.2.1.0 and must be updated or hardened against unauthenticated LDAP access.
Risk and Exploitability
The CVSS base score of 9.8 denotes a very high severity. With an EPSS below 1% and not listed in the CISA KEV catalog, the current exploitation probability is low but the vulnerability is easily exploitable from a network perspective. An attacker does not need privileged access or a local foothold; simply connecting to the LDAP service suffices to trigger the compromise.
OpenCVE Enrichment