Multiple security vulnerabilities affecting OpenDJ versions All four OpenDJ vulnerabilities affect versions 5 have been identified in OpenDJ, a high-value target for enterprises due to its role in identity, authentication, and access control. The affected version range is 5.1.1 and earlier.
CVE-2026-62373 (CVSS 6.6): A user with JMX_READ can drive Java deserialization through MBean arguments since no serial filter applies.[/subscribe_to_unlock_form]
Multiple security vulnerabilities affecting OpenDJ versions All four OpenDJ vulnerabilities affect versions 5 have been identified in OpenDJ, a high-value target for enterprises due to its role in identity, authentication, and access control. The affected version range is 5.1.1 and earlier.
CVE-2026-62373 (CVSS 6.6): A user with JMX_READ can drive Java deserialization through MBean arguments since no serial filter applies.[emaillocker id="1283"]
CVE-2026-62375 (CVSS 7.5): A single crafted VLV search request can exhaust server memory, a denial of service reachable in a default configuration. These vulnerabilities collectively present significant risks to OpenDJ deployments. These vulnerabilities collectively present significant risks to OpenDJ deployments.
These vulnerabilities collectively present significant risks to OpenDJ deployments.
We recommend you to update OpenDJ to version 5.1.2.
The following reports contain further technical details:
[/emaillocker]