CVE-2019-13057: Apple Mac OS X

Medium severity, CVSS 4.9. EPSS: 3.4% chance of exploitation in the next 30 days.

An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.)

Affected products

  • Apple Mac OS X: from 10.13, before 10.13.6 (fixed in 10.13.6); from 10.14, before 10.14.6 (fixed in 10.14.6); from 10.15, before 10.15.2 (fixed in 10.15.2); version 10.13.6 only; version 10.14.6 only
  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 18.04 only; version 19.04 only
  • Debian Debian Linux: version 8.0 only
  • McAfee Policy Auditor: before 6.5.1 (fixed in 6.5.1); version 6.5.1 only
  • Openldap Openldap: before 2.4.48 (fixed in 2.4.48)
  • Opensuse Leap: version 15.0 only; version 15.1 only
  • Oracle Blockchain Platform: before 21.1.2 (fixed in 21.1.2)
  • Oracle Solaris: version 11 only
  • Oracle ZFS Storage Appliance Kit: version 8.8 only

Published 2019-07-26. Last modified 2026-06-17.