Impact
An unauthenticated attacker can exploit a flaw in the Oracle Internet Directory LDAP server when given network access to an LDAP port. The flaw allows the attacker to obtain full control of the directory service. Based on the description, it is inferred that the attacker could retrieve all configuration data and user information, and potentially use the compromised service for lateral movement. The result is total compromise, affecting confidentiality, integrity and availability, as indicated by the CVSS base score of 9.8.
Affected Systems
Oracle Internet Directory, part of Oracle Fusion Middleware, runs versions 12.2.1.4.0 and 14.1.2.1.0. The vulnerability is present in the LDAP server component, and any installation of those versions with the LDAP service accessible to a network attacker is at risk.
Risk and Exploitability
The CVSS base score of 9.8 denotes a very high severity. With an EPSS below 1% and not listed in the CISA KEV catalog, the current exploitation probability is low, but the vulnerability is easily exploitable from a network perspective. An attacker does not need privileged access or a local foothold; simply connecting to the LDAP service suffices to trigger the compromise.
OpenCVE Enrichment