Impact
The Apache Directory LDAP API contains an asymmetrical resource consumption vulnerability that can lead to a denial of service. When an LDAP server processes specially crafted telephone numbers, the API may exhaust a CPU core indefinitely. This results in a loss of service for legitimate clients, while confidentiality and integrity remain unchanged.
Affected Systems
The vulnerability is present in Apache Directory LDAP API versions 2.1.0 through 2.1.8. Any LDAP server, such as Apache Directory Server, that relies on this API falls within the affected scope.
Risk and Exploitability
The CVSS and EPSS metrics are not reported, but the impact of consuming 100% of a CPU core indefinitely is severe. The flaw is triggered by remote LDAP requests, so an attacker can induce the denial of service over the network. No public exploit has been documented and the vulnerability is not listed in CISA KEV, yet the lack of a fix can enable sustained service disruption.
OpenCVE Enrichment