Executive brief
Oracle Internet Directory is a critical directory service used in Oracle Fusion Middleware to manage user identities and access across enterprise systems. A low-privilege attacker with network access can exploit a vulnerability in the LDAP server component to gain complete control of the directory service and potentially compromise other connected Oracle products, leading to unauthorized access to sensitive business data and system disruption.
Technical details
The vulnerability exists in the OID LDAP Server component of Oracle Internet Directory in versions 12.2.1.4.0 and 14.1.2.1.0. It is easily exploitable by a low-privileged attacker with network access via LDAP protocol, requiring no user interaction. Successful exploitation results in complete takeover of Oracle Internet Directory with impacts to confidentiality, integrity, and availability. The scope is marked as changed, indicating that exploitation of this vulnerability in Oracle Internet Directory can significantly impact other Oracle Fusion Middleware components. No patch availability information is provided in the advisory.
Affected products
- Oracle Internet Directory 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-09-15: disclosed