Impact
This vulnerability allows sensitive LDAP data to be transmitted in cleartext after initiating a StartTLS operation. An attacker who can observe traffic between the LDAP client and server can read authentication credentials or query responses before the TLS handshake is fully established. The weakness is an exposure of sensitive information to an unauthorized target, consistent with CWE-345. The effect is a confidentiality break that could compromise sensitive organizational data.
Affected Systems
Affected systems are Apache Directory LDAP API versions from 2.1.0 through 2.1.8. The products are listed under Apache Software Foundation:Apache Directory LDAP API. Clients and servers using these versions may be vulnerable when a Search request is sent and a StartTLS extended operation begins before the handshake completes.
Risk and Exploitability
The CVSS score is not provided, and the EPSS score is unavailable. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a network man‑in‑the‑middle that can capture traffic between client and server. The risk is moderate to high in environments where LDAP traffic is not otherwise encrypted, and mitigation requires updating to 2.1.9 or applying a workaround to avoid plaintext traffic during the handshake.
OpenCVE Enrichment