LDAP Entry Poisoning Vulnerability in Apache Groovy LDAP API
CVE-2016-6497
7.5HIGH
What is CVE-2016-6497?
The Groovy LDAP API in Apache is susceptible to LDAP entry poisoning attacks due to a misconfiguration that enables the returnObjFlag setting for all search methods. This flaw allows attackers to manipulate LDAP entries, potentially leading to unauthorized data exposure or integrity issues. Security measures should be implemented to address this vulnerability and protect sensitive information from being compromised.