CVE-2016-6497

HIGH

Apache Groovy LDAP - LDAP Entry Poisoning via returnObjFlag Setting

Title source: llm
STIX 2.1

Description

main/java/org/apache/directory/groovyldap/LDAP.java in the Groovy LDAP API in Apache allows attackers to conduct LDAP entry poisoning attacks by leveraging setting returnObjFlag to true for all search methods.

Scores

CVSS v3 7.5
EPSS 0.0301
EPSS Percentile 86.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-254
Status published
Products (1)
apache/groovy_ldap
Published Jan 18, 2017
Tracked Since Feb 18, 2026