LDAP Entry Poisoning Vulnerability in Apache Groovy LDAP API
CVE-2016-6497
7.5HIGH
Summary
The Groovy LDAP API in Apache is susceptible to LDAP entry poisoning attacks due to a misconfiguration that enables the returnObjFlag setting for all search methods. This flaw allows attackers to manipulate LDAP entries, potentially leading to unauthorized data exposure or integrity issues. Security measures should be implemented to address this vulnerability and protect sensitive information from being compromised.
References
EPSS Score
5% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved