The fix in comment 22 works:
eval "$(ucr shell)"; echo -e "dn: cn=default,cn=ppolicy,cn=univention,$ldap_base\nchangetype: modify\nreplace: pwdAllowUserChange\npwdAllowUserChange: TRUE" \
| ldapmodify -D "cn=admin,$ldap_base" -y /etc/ldap.secret