Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-6497

Опубликовано: 29 окт. 2016
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

main/java/org/apache/directory/groovyldap/LDAP.java in the Groovy LDAP API in Apache allows attackers to conduct LDAP entry poisoning attacks by leveraging setting returnObjFlag to true for all search methods.

A flaw was found in Groovy LDAP. The API in Apache allows attackers to conduct LDAP entry poisoning attacks by leveraging the returnObjFlag setting. The highest threat from this vulnerability is to data integrity.

Отчет

The vulnerable class LDAP, is not found in OpenShift Container Platform's distribution of ElasticSearch. Groovy as shipped in Red Hat Enterprise Linux 7 does not embed the LDAP class, and thus is not affected by this vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7groovyNot affected
Red Hat Fuse 7camelNot affected
Red Hat JBoss BRMS 5groovyOut of support scope
Red Hat JBoss Data Virtualization 6groovyOut of support scope
Red Hat JBoss Enterprise Application Platform 5groovyOut of support scope
Red Hat JBoss Enterprise Application Platform 6groovyOut of support scope
Red Hat JBoss Fuse 6camelNot affected
Red Hat JBoss Fuse Service Works 6camelOut of support scope
Red Hat JBoss Operations Network 3groovyOut of support scope
Red Hat JBoss SOA Platform 5groovyOut of support scope

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-358
https://bugzilla.redhat.com/show_bug.cgi?id=1844510groovy: allows attackers to conduct LDAP entry poisoning attacks by leveraging setting returnObjFlag to true for all search methods

EPSS

Процентиль: 86%
0.03008
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
около 9 лет назад

main/java/org/apache/directory/groovyldap/LDAP.java in the Groovy LDAP API in Apache allows attackers to conduct LDAP entry poisoning attacks by leveraging setting returnObjFlag to true for all search methods.

CVSS3: 7.5
github
больше 3 лет назад

main/java/org/apache/directory/groovyldap/LDAP.java in the Groovy LDAP API in Apache allows attackers to conduct LDAP entry poisoning attacks by leveraging setting returnObjFlag to true for all search methods.

EPSS

Процентиль: 86%
0.03008
Низкий

7.5 High

CVSS3