Embedding servers that use the affected API and have not set MAX_PDU_SIZE_ATTR can be reached by an unauthenticated pre-bind client using the same malicious BER bytes. Clients are also exposed when communicating with a malicious LDAP peer or when a man-in-the-middle can alter responses.
The attacker needs to send a small BER-encoded response that specifies an excessive allocation size, then may stall the connection. A handful of connections can exhaust the JVM heap or retain large allocations per connection.
No. The advisory states that an OutOfMemoryError bypasses the DecoderException handlers, so relying on those handlers does not prevent the client JVM from running out of memory.
Upgrade Apache Directory LDAP API to version 1.2.9. For embedding servers, setting MAX_PDU_SIZE_ATTR is specifically identified as relevant to preventing the unauthenticated pre-bind path described in the advisory.