Impact
Spring Security’s embedded UnboundID LDAP server automatically registers a default administrative credential and binds to all network interfaces. This exposure allows attackers to discover a well‑known bind DN and gain administrative access to the LDAP directory. Such privileged access can compromise confidentiality, integrity, and availability of directory data and all services relying on it.
Affected Systems
Affected releases include Spring Security 7.1.0, 7.0.0‑7.0.6, 6.5.0‑6.5.11, 6.4.0‑6.4.18, 5.8.0‑5.8.27, and 5.7.0‑5.7.25. The vulnerability resides in the UnboundID LDAP integration bundled with these versions.
Risk and Exploitability
The CVSS score of 9.4 indicates high severity. No EPSS data is available, and the vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit the exposed administrative DN over any network interface the server listens on, making local or remote network compromise a realistic threat. Lacking additional authentication controls, an attacker with network reach can perform LDAP administration without further credentials.
OpenCVE Enrichment