CVE-2026-60895: Medium severity Oracle Oracle Unified Directory vulnerability
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Unified Directory accessible data as well as unauthorized access to critical data or complete access to all Oracle Unified Directory accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 12.2.1.4.0Patch Oracle Fusion Middleware - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.1.2.1.0Patch Oracle Fusion Middleware
Event History
Frequently Asked Questions
Which deployments are affected?
The affected supported Oracle Unified Directory versions are 12.2.1.4.0 and 14.1.2.1.0, specifically the OUD Core component.
What access does an attacker need?
An attacker needs low-privileged access and network access to the LDAP service. User interaction is not required, but exploitation is described as difficult due to high attack complexity.
What could a successful attack allow?
A successful attack can allow unauthorized reading, creation, deletion, or modification of critical data, potentially affecting all data accessible through Oracle Unified Directory. The stated impact is confidentiality and integrity; availability is not affected.