org.openidentityplatform.opendj:opendj-server-legacy
Maven3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.openidentityplatform.opendj:opendj-server-legacypage 1 of 1
- CVE-2025-27497HIGHCVSS 8.7EG 8.7✓ Fixed in 4.9.32025-03-05
vulnerable: 4.4.10 ... 4.9.2 (31 versions)
OpenDJ is an LDAPv3 compliant directory service. OpenDJ prior to 4.9.3 contains a denial-of-service (DoS) vulnerability that causes the server to become unresponsive to all LDAP requests without crashing or restarting. This issue occurs wh…
- CVE-2026-46495CRITICALCVSS 9.2EG 9.2✓ Fixed in 5.1.12026-06-22
vulnerable: 4.10.0 ... 5.1.0 (41 versions)
OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.1, the JMX RMI connector in opendj-server-legacy/src/main/java/org/opends/server/protocols/jmx/RmiConnector.java processes attacker-controlled credential objects before authenti…
- CVE-2026-73644CRITICALCVSS 9.6EG 9.6✓ Fixed in 5.1.22026-08-13
vulnerable: 4.10.0 ... 5.1.1 (42 versions)
OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.2, the SASL PLAIN authorization identity path in opendj-server-legacy/src/main/java/org/opends/server/extensions/PlainSASLMechanismHandler.java checked the PROXIED_AUTH privileg…
Check whether org.openidentityplatform.opendj:opendj-server-legacy is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.openidentityplatform.opendj:opendj-server-legacy CVEs against the assets you own.
Start Free Scan →