Executive brief
Oracle Internet Directory is a directory service used to manage user identities and access across Oracle enterprise systems. This vulnerability allows an unauthenticated attacker on the network to gain complete control over the directory service without authentication, potentially compromising user credentials and system access across dependent applications. The impact extends beyond the directory itself to other Oracle Fusion Middleware components that rely on it.
Technical details
This is a remote code execution vulnerability in the Oracle Internet Directory LDAP server component, exploitable without authentication from network-accessible LDAP ports. The vulnerability has a CVSS 3.1 score of 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H), indicating maximum severity with scope change affecting dependent systems. Affected versions are 12.2.1.4.0 and 14.1.2.1.0. The exact root cause and patch status are not detailed in the advisory, but the Critical severity classification indicates an urgent fix is likely available or in development.
Affected products
- Oracle Oracle Internet Directory 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-09-15: disclosed