Ensure LDAP is not enabled
The Lightweight Directory Access Protocol (LDAP) was introduced as a replacement for NIS/YP. It is a service that provides a method for looking up information from a central database.
[yes/no]
If the server will not need to act as an LDAP client or server, it is recommended that the software be disabled to reduce the potential attack surface.
Fix:
Uninstall the slapd package:
# apt-get purge slapd
oval:org.secpod.oval:def:55154
SCAP Repo OVAL Definition
2019-06-19