Executive brief
Oracle Internet Directory is a directory service used for managing user identities and access across enterprise applications. An unauthenticated network attacker can exploit this vulnerability to completely compromise the directory, potentially gaining control over user authentication and access controls for all connected systems.
Technical details
This is an authentication bypass vulnerability in Oracle Internet Directory's LDAP server component. An unauthenticated attacker with network-level access to the LDAP service can exploit the flaw without credentials or user interaction required. The vulnerability allows complete compromise of the directory service, resulting in full confidentiality, integrity, and availability impact. Affected versions are 12.2.1.4.0 and 14.1.2.1.0; patch availability should be verified through Oracle's security bulletins.
Affected products
- Oracle Internet Directory 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-09-15: disclosed