Executive brief
Oracle Unified Directory, a directory service used for managing identity and access data, is vulnerable to a denial-of-service attack. An unauthenticated attacker can remotely cause the system to hang or crash repeatedly. This can disrupt business operations by preventing users and applications from authenticating or accessing directory information.
Technical details
A vulnerability in the OUD Core component of Oracle Unified Directory allows for a denial-of-service (DoS) attack. The flaw is easily exploitable by an unauthenticated attacker with network access via the LDAP protocol. Successful exploitation results in a frequently repeatable crash or a system hang, leading to a complete loss of availability. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.1.0. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Unified Directory 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory