Executive brief
Oracle Virtual Directory is a service that provides a single point of access to multiple data sources, such as databases and directories. A critical security flaw allows an unauthorized person to take complete control of this service over the network. This could lead to the theft of sensitive identity data, unauthorized modification of user records, or a total shutdown of the directory service.
Technical details
A critical vulnerability exists in the Virtual Directory Server component of Oracle Virtual Directory (part of Oracle Fusion Middleware). The flaw is categorized as an improper access control issue (CWE-284) that is easily exploitable. An unauthenticated attacker can exploit this vulnerability over the network via the LDAP protocol without any user interaction. A successful exploit results in a complete takeover of the Oracle Virtual Directory instance, impacting confidentiality, integrity, and availability. Affected versions include 12.2.1.4.0 and 14.1.2.0.0.
Affected products
- Oracle Virtual Directory 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle Critical Patch Update published