CVE-2016-6497

Severity CVSS v4.0:
Pending analysis
Type:
CWE-254 Security Features
Publication date:
18/01/2017
Last modified:
20/04/2025

Description

main/java/org/apache/directory/groovyldap/LDAP.java in the Groovy LDAP API in Apache allows attackers to conduct LDAP entry poisoning attacks by leveraging setting returnObjFlag to true for all search methods.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:groovy_ldap:*:*:*:*:*:*:*:*