CVE-2016-6500

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
03/02/2017
Last modified:
20/04/2025

Description

Unspecified methods in the RACF Connector component before 1.1.1.0 in ForgeRock OpenIDM and OpenICF improperly call the SearchControls constructor with returnObjFlag set to true, which allows remote attackers to execute arbitrary code via a crafted serialized Java object, aka LDAP entry poisoning.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:forgerock:racf_connector:*:*:*:*:*:*:*:* 1.1.0.0 (including)