OPENDJ 5.1.2 addresses four security vulnerabilities, including a CVSS 9.6 authorization bypass and a CVSS 9.4 unauthenticated SSRF, both of which pose significant risks to identity and access control. The authorization bypass allows arbitrary non-root identity assumption due to improper handling of the proxied-auth privilege. The SSRF vulnerability enables remote attackers to make server-side requests to internal services, heightening the risk of data breaches.
Two lower-severity issues include JMX deserialization and VLV search request causing memory exhaustion. All vulnerabilities affect versions 5.1.1 and earlier; 5.1.2 provides necessary fixes. Users are advised to upgrade and also implement interim protective measures.