Description of problem: After the patch was released for CVE-2022-0996, anonymously binding to reset a password is broken. Version-Release number of selected component (if applicable): 389-ds-base-1.3.10.2-16.el7_9.x86_64 How reproducible: Customer is able to reproduce. Actual results: WARNING: Your password has expired. You must change your password now and login again! Changing password for user jdoe. Current Password: New password: Retype new password: Password change failed. Server message: Anonymous Binds are not allowed. Expected results: WARNING: Your password has expired. You must change your password now and login again! Changing password for user jdoe. Current Password: New password: Retype new password: passwd: all authentication tokens updated successfully. Additional info: Other associated logs on 389ds server: --- [31/Jan/2023:16:01:50.153878056 +0000] - DEBUG - NS7bitAttr - preop_modify - MODIFY begin [31/Jan/2023:16:01:50.154051469 +0000] - DEBUG - passwd_modify_extop - Received extended operation request with OID 1.3.6.1.4.1.4203.1.11.1 [31/Jan/2023:16:01:50.154084267 +0000] - DEBUG - passwd_modify_extop - Password Modify extended operation request confirmed.[31/Jan/2023:16:01:50.154110386 +0000] - DEBUG - passwd_modify_extop - Anonymous Binds are not allowed. --- On the host: --- (2023-01-31 18:14:47): [be[my.domain]] [simple_bind_done] (0x0400): Bind result: Invalid credentials(49), password expired! (2023-01-31 18:14:47): [be[my.domain]] [sdap_exop_modify_passwd_send] (0x0100): Executing extended operation (2023-01-31 18:14:47): [be[my.domain]] [sdap_exop_modify_passwd_done] (0x0200): Server returned no controls. (2023-01-31 18:14:47): [be[my.domain]] [sdap_exop_modify_passwd_done] (0x0080): ldap_extended_operation result: Insufficient access(50), Anonymous Binds are not allowed. ---