Vulnerability Description
The LDAP directory connector in Atlassian Crowd before 2.8.8 and 2.9.x before 2.9.5 allows remote attackers to execute arbitrary code via an LDAP attribute with a crafted serialized Java object, aka LDAP entry poisoning.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Atlassian | Crowd | <= 2.8.4 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/archive/1/539655/100/0/threaded
- http://www.securityfocus.com/bid/93826Third Party AdvisoryVDB Entry
- https://confluence.atlassian.com/crowd/crowd-security-advisory-2016-10-19-856697Vendor Advisory
- https://jira.atlassian.com/browse/CWD-4790Issue Tracking
- https://www.blackhat.com/docs/us-16/materials/us-16-Munoz-A-Journey-From-JNDI-LDNot Applicable
- http://www.securityfocus.com/archive/1/539655/100/0/threaded
- http://www.securityfocus.com/bid/93826Third Party AdvisoryVDB Entry
- https://confluence.atlassian.com/crowd/crowd-security-advisory-2016-10-19-856697Vendor Advisory
- https://jira.atlassian.com/browse/CWD-4790Issue Tracking
- https://www.blackhat.com/docs/us-16/materials/us-16-Munoz-A-Journey-From-JNDI-LDNot Applicable
FAQ
What is CVE-2016-6496?
CVE-2016-6496 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The LDAP directory connector in Atlassian Crowd before 2.8.8 and 2.9.x before 2.9.5 allows remote attackers to execute arbitrary code via an LDAP attribute with a crafted serialized Java object, aka L...
How severe is CVE-2016-6496?
CVE-2016-6496 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2016-6496?
Check the references section above for vendor advisories and patch information. Affected products include: Atlassian Crowd.