Executive brief
Oracle Internet Directory is a directory server component of Oracle Fusion Middleware used to manage user identities and access controls. A high-privileged authenticated attacker can exploit a network-accessible LDAP service to completely compromise the directory server, potentially affecting all systems and applications that rely on it for authentication and authorization.
Technical details
This vulnerability in the Oracle Internet Directory OID LDAP Server component affects versions 12.2.1.4.0 and 14.1.2.1.0. The issue is exploitable by a high-privileged attacker with network access to the LDAP service (attack vector: network, requires elevated privileges). Successful exploitation results in complete compromise of Oracle Internet Directory, affecting confidentiality, integrity, and availability of the directory service and dependent authentication systems. The vulnerability has a CVSS 3.1 score of 7.2 with a vector of AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H. Patch status and specific technical details regarding the root cause are not disclosed in available references.
Affected products
- Oracle Internet Directory 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-09-15: disclosed