Threat Advisory

OpenDJ Flaws Bypass Authorization and Enable SSRF Attacks

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting OpenDJ versions All four OpenDJ vulnerabilities affect versions 5 have been identified in OpenDJ, a high-value target for enterprises due to its role in identity, authentication, and access control. The affected version range is 5.1.1 and earlier.

CVE-2026-62373 (CVSS 6.6): A user with JMX_READ can drive Java deserialization through MBean arguments since no serial filter applies.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting OpenDJ versions All four OpenDJ vulnerabilities affect versions 5 have been identified in OpenDJ, a high-value target for enterprises due to its role in identity, authentication, and access control. The affected version range is 5.1.1 and earlier.

CVE-2026-62373 (CVSS 6.6): A user with JMX_READ can drive Java deserialization through MBean arguments since no serial filter applies.[emaillocker id="1283"]

CVE-2026-62375 (CVSS 7.5): A single crafted VLV search request can exhaust server memory, a denial of service reachable in a default configuration. These vulnerabilities collectively present significant risks to OpenDJ deployments. These vulnerabilities collectively present significant risks to OpenDJ deployments.

These vulnerabilities collectively present significant risks to OpenDJ deployments.

RECOMMENDATION:

We recommend you to update OpenDJ to version 5.1.2.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu