Impact
OpenDJ versions before 5.1.1 contain a flaw in the JMX RMI connector that processes attacker‑controlled credential objects before authentication. Because the connector does not enforce a restrictive credential filter and the authentication routine accepts an unconstrained Object array, an unauthenticated attacker can craft a serialized Java object and have it deserialized by the server. Delivering the payload to the open TCP listener for the JMX Connection Handler—enabled by default only in the legacy module—allows the attacker to execute arbitrary code in the OpenDJ process. The vulnerability depends on the runtime classpath and the Java runtime; code‑execution was shown on OpenDJ 4.4.15 running JDK 11 with Jackson 2.12.6.1. This flaw is a Java deserialization vulnerability (CWE‑502).
Affected Systems
The affected products are OpenIdentityPlatform OpenDJ and the opendj-server-legacy module, for all releases older than 5.1.1, including the 4.4.15 build that was successfully exploited. The JMX Connection Handler is disabled by default but must be enabled to be vulnerable.
Risk and Exploitability
The CVSS score of 9.2 indicates critical severity, and the EPSS score is less than 1%, suggesting limited current exploitation activity. The vulnerability is not listed in the CISA KEV catalog. An attacker only needs network visibility to the JMX RMI service; the TCP listener must be reachable and the JMX Connection Handler enabled. Once accessed, the attacker can send a crafted object to trigger deserialization and gain full code execution in the OpenDJ server process, with no authentication required. The risk remains high due to the critical CVSS rating and the potential for remote code execution.
OpenCVE Enrichment
Github GHSA