Impact
The vulnerability resides in Oracle Internet Directory’s LDAP server component and permits a high‑privileged attacker who can reach the server over the network to take over the application. Once exploited, the attacker gains to the underlying operating system. The flaw delivers confidentiality, integrity, and availability impacts with a CVSS 3.1 base score of 7.2.
Affected Systems
Affected versions are Oracle Internet Directory 12.2.1.4.0 and 14.1.2.1.0. The issue applies to all deployments of the Oracle Fusion Middleware suite that include these OID releases.
Risk and Exploitability
The attack vector is a network‑based LDAP connection; no local privilege or code execution is required beyond the ability to query the LDAP service. The EPSS score is below 1 %, indicating a low likelihood of exploitation in the wild, and the vulnerability is not listed in CISA KEV. Nevertheless, the high impact score and the ability to fully compromise the directory warrants immediate action.
OpenCVE Enrichment