Spring Security’s critical UnboundID LDAP flaw could let remote attackers gain admin access to exposed in-memory LDAP directories.