Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Internet Directory. While the vulnerability is in Oracle Internet Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Internet Directory. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cspuaug2026.html |
|
History
Mon, 24 Aug 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated LDAP Access Enabling Full Compromise in Oracle Internet Directory |
Mon, 24 Aug 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 |
Sat, 22 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 21 Aug 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated LDAP Access Enabling Full Compromise in Oracle Internet Directory |
Fri, 21 Aug 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated LDAP Vulnerability Allowing Full Compromise of Oracle Internet Directory | |
| Weaknesses | CWE-284 CWE-287 |
Thu, 20 Aug 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | NVD-CWE-noinfo |
Wed, 19 Aug 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated LDAP Vulnerability Allowing Full Compromise of Oracle Internet Directory | |
| Weaknesses | CWE-284 CWE-287 |
Tue, 18 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Internet Directory. While the vulnerability is in Oracle Internet Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Internet Directory. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). | |
| First Time appeared |
Oracle
Oracle internet Directory |
|
| CPEs | cpe:2.3:a:oracle:internet_directory:12.2.1.4.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:internet_directory:14.1.2.1.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Oracle
Oracle internet Directory |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: oracle
Published: 2026-08-18T20:59:54.183Z
Updated: 2026-08-25T15:22:47.567Z
Reserved: 2026-07-08T15:52:20.742Z
Link: CVE-2026-61241
Updated: 2026-08-21T15:01:44.527Z
Status : Modified
Published: 2026-08-18T21:16:56.467
Modified: 2026-08-24T17:17:30.883
Link: CVE-2026-61241
No data.