Impact
A small BER-encoded response can trigger the LDAP API to allocate a memory block with an overly large size value. The resulting OutOfMemoryError bypasses normal decoder exceptions and can cause the entire client JVM to crash or the server to stall. Because the allocation happens before any data is processed, the attack can be carried out remotely by a connection peer or a MITM attacker. The primary consequence is a denial of service that can exhaust the heap and keep the service unavailable until a restart or manual intervention. This weakness corresponds to the "Excessive Allocation" category associated with CWE-770 and CWE-789.
Affected Systems
The vulnerability affects the Apache Directory LDAP API distributed by the Apache Software Foundation. Versions 1.2.0 through the last entry before 1.2.9 are susceptible. Any client or embedding server that uses a pre‑bind client without setting a maximum PDU size attribute can be impacted.
Risk and Exploitability
The CVSS score is 7.5, indicating a high severity vulnerability, and the EPSS score is less than 1%, suggesting a low but nonzero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers need no authentication and can target any open LDAP connection, making the potential impact significant. Because a handful of poorly throttled connections can exhaust the heap, large-scale denial of service is achievable with minimal effort. While no public exploit has been documented, the vulnerability remains a low-hanging fruit for adversaries once a suitable client exists.
OpenCVE Enrichment