An attacker can use the unrestricted LDAP queries to determine configuration entries
https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-29542
https://backstage.forgerock.com/knowledge/kb/article/a90639318
https://backstage.forgerock.com/downloads/browse/am/featured