Executive brief
Oracle Internet Directory is a directory service used to manage user identities and authentication across enterprise systems. An unauthenticated attacker on the network can exploit this vulnerability in the LDAP server to bypass authentication and gain complete control of the directory service, potentially compromising access to all systems that rely on it for user management and authentication.
Technical details
This vulnerability affects the LDAP server component of Oracle Internet Directory and allows unauthenticated attackers to compromise the system via LDAP protocol. The vulnerability is easily exploitable due to low attack complexity and requires no privileges or user interaction. Successful exploitation results in complete takeover of the Oracle Internet Directory, affecting both confidentiality, integrity, and availability of the directory service. The affected versions are 12.2.1.4.0 and 14.1.2.1.0; patch status and mitigation details are not yet available in public advisory sources.
Affected products
- Oracle Internet Directory 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-09-15: disclosed