Vulnerability Description
JFrog Artifactory before 4.11 allows remote attackers to execute arbitrary code via an LDAP attribute with a crafted serialized Java object, aka LDAP entry poisoning.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jfrog | Artifactory | <= 4.10 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/94855
- https://www.blackhat.com/docs/us-16/materials/us-16-Munoz-A-Journey-From-JNDI-LDNot Applicable
- https://www.jfrog.com/confluence/display/RTF/Release+Notes#ReleaseNotes-MainUpdaRelease NotesVendor Advisory
- http://www.securityfocus.com/bid/94855
- https://www.blackhat.com/docs/us-16/materials/us-16-Munoz-A-Journey-From-JNDI-LDNot Applicable
- https://www.jfrog.com/confluence/display/RTF/Release+Notes#ReleaseNotes-MainUpdaRelease NotesVendor Advisory
FAQ
What is CVE-2016-6501?
CVE-2016-6501 is a vulnerability with a CVSS score of 9.8 (CRITICAL). JFrog Artifactory before 4.11 allows remote attackers to execute arbitrary code via an LDAP attribute with a crafted serialized Java object, aka LDAP entry poisoning.
How severe is CVE-2016-6501?
CVE-2016-6501 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2016-6501?
Check the references section above for vendor advisories and patch information. Affected products include: Jfrog Artifactory.