An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.)
https://www.oracle.com/security-alerts/cpuapr2022.html
https://www.oracle.com/security-alerts/cpuapr2020.html
https://www.openldap.org/lists/openldap-announce/201907/msg00001.html
https://www.openldap.org/its/?findid=9038
https://usn.ubuntu.com/4078-2/
https://usn.ubuntu.com/4078-1/
https://support.apple.com/kb/HT210788
https://security.netapp.com/advisory/ntap-20190822-0004/
https://seclists.org/bugtraq/2019/Dec/23
https://lists.debian.org/debian-lts-announce/2019/08/msg00024.html
https://kc.mcafee.com/corporate/index?page=content&id=SB10365
http://seclists.org/fulldisclosure/2019/Dec/26
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00058.html
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00053.html