ZeroHour

CVE-2016-6497

CVSS 3.1
7.5 high
EPSS
6%p93
Published
()
Modified
Description

main/java/org/apache/directory/groovyldap/LDAP.java in the Groovy LDAP API in Apache allows attackers to conduct LDAP entry poisoning attacks by leveraging setting returnObjFlag to true for all search methods.

Vendors
apache
Products
groovy ldap
Weakness
CWE-254
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.