Impact
Vulnerability in the Oracle Internet Directory product enables an attacker without authentication to execute arbitrary code and fully compromise the directory service. The flaw is in the LDAP server component and can be exploited from outside the host over network protocols such as T3 and IIOP. Successful exploitation results in complete takeover, affecting confidentiality, integrity, and availability of the directory.
Affected Systems
Oracle Internet Directory versions 12.2.1.4.0 and 14.1.2.1.0 are affected. The product is distributed by Oracle Corporation.
Risk and Exploitability
The vulnerability carries a CVSS 3.1 base score of 9.8, indicating critical severity. The EPSS score is below 1 %, showing a low but nonzero probability of attack, and it is not yet catalogued in CISA KEV. The likely attack vector is remote network access via the exposed T3 and IIOP ports; an attacker can trigger the flaw without authentication and immediately gain full control over the directory service.
OpenCVE Enrichment