Unspecified methods in the RACF Connector component before 1.1.1.0 in ForgeRock OpenIDM and OpenICF improperly call the SearchControls constructor with returnObjFlag set to true, which allows remote attackers to execute arbitrary code via a crafted serialized Java object, aka LDAP entry poisoning.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: hpe

Published: 2017-02-03T19:00:00

Updated: 2017-02-03T19:57:02

Reserved: 2016-08-01T00:00:00


Link: CVE-2016-6500

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2017-02-03T19:59:00.223

Modified: 2017-03-02T15:02:20.520


Link: CVE-2016-6500

JSON object: View

cve-icon Redhat Information

No data.

CWE