Executive brief
Oracle Internet Directory is a directory service component of Oracle Fusion Middleware used to store and manage user and resource information across enterprise systems. This vulnerability allows an unauthenticated attacker on the network to gain complete control over the directory service without authentication, enabling them to read sensitive data, modify configurations, or disrupt directory operations that other applications depend on.
Technical details
This is a remote code execution or authentication bypass vulnerability in the OID LDAP Server component, accessible via the T3 and IIOP protocols. The vulnerability requires no authentication and can be exploited by an unauthenticated attacker with network access to the affected service. Successful exploitation results in complete takeover of the Oracle Internet Directory, allowing the attacker to compromise confidentiality, integrity, and availability of the directory service. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.1.0 of Oracle Internet Directory. Patch availability information is not provided in the advisory.
Affected products
- Oracle Internet Directory 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-09-15: disclosed