REDHAT-BUG-2091781: Medium severity 389 Directory Server 389-ds-base vulnerability
mishandling of the filter that would yield incorrect results, but as that has progressed, we have determined that it actually is an access control bypass. This may allow any remote un-authenticated user to issue a filter that allows searching for database items they do not have access to, including but not limited to potentially userPassword hashes and other sensitive data.
https://github.com/389ds/389-ds-base/issues/5170