Impact
Oracle Internet Directory versions 12.2.1.4.0 and 14.1.2.1.0 contain an authentication bypass vulnerability that allows an unauthenticated attacker with network access to the LDAP service to compromise the directory. The flaw maps to CWE‑287 (Improper Authentication) and CWE‑306 (Missing Authentication for Critical Function). Because the LDAP protocol is exposed, a successful exploit could grant the attacker full control over the directory, enabling data theft, configuration changes, or service takeover, with complete confidentiality, integrity, and availability compromise.
Affected Systems
The affected product is Oracle Internet Directory, part of Oracle Fusion Middleware. Affected releases include 12.2.1.4.0 and 14.1.2.1.0. Vulnerable versions are identified by the CPE strings for 12.2.1.4.0 and 14.1.2.1.0.
Risk and Exploitability
The CVSS 3.1 score of 9.8 signals a critical threat with high impact. The EPSS score of less than 1% indicates that, so far, exploitation attempts are rare, but the vulnerability remains easily exploitable by any actor with network access to the LDAP port. The issue is not yet listed in CISA KEV, yet the combination of high severity and unrestricted LDAP exposure makes it a high‑risk target. Attackers would likely perform the exploit from behind a network edge, sending specially crafted LDAP requests to induce an unauthenticated bind that yields control of the directory service.
OpenCVE Enrichment