Impact
The Apache Directory LDAP API has a deserialization flaw that allows an attacker to inject a serialized Java class through the loadSchema() subschema search. When an LDAP server or a pre‑TLS man‑in‑the‑mid‑point returns a schema object containing that class, the client deserializes it without validation, potentially leading to remote code execution on the system hosting the API. This vulnerability is identified as CWE‑502 and can compromise the confidentiality, integrity, and availability of the affected application.
Affected Systems
The flaw exists in Apache Directory LDAP API versions from 2.1.0 up through 2.1.8 inclusive. Any deployment that uses these releases and performs loadSchema() requests against an LDAP server that is not strictly trusted is vulnerable. The issue does not affect releases prior to 2.1.0 or the patched 2.1.9 variant.
Risk and Exploitability
An attacker can exploit the vulnerability by controlling an LDAP server or positioning a pre‑TLS interception that supplies a malicious schema during a loadSchema() call. While no CVSS score or EPSS value is published, the absence of a KEV listing suggests it has not yet been actively exploited. Nevertheless, the payload can grant arbitrary code execution; therefore the potential impact is severe. Mitigation relies on upgrading to 2.1.9, using TLS, and ensuring only trusted servers are queried.
OpenCVE Enrichment