CVE-2015-5349: Apache Directory Studio

High severity, CVSS 7.8. EPSS: 2.1% chance of exploitation in the next 30 days.

The CSV export in Apache LDAP Studio and Apache Directory Studio before 2.0.0-M10 does not properly escape field values, which might allow attackers to execute arbitrary commands by leveraging a crafted LDAP entry that is interpreted as a formula when imported into a spreadsheet.

Affected products

  • Apache Directory Studio: version 1.0.0 only; version 1.0.1 only; version 1.1.0 only; version 1.2.0 only; version 1.3.0 only; version 1.4.0 only; …
  • Apache LDAP Studio: version 0.6.0 only; version 0.7.0 only; version 0.8.0 only; version 0.8.1 only

Published 2016-04-11. Last modified 2026-06-17.