CVE-2016-6496: Input Validation
Published Dec 9, 2016
·Updated
The LDAP directory connector in Atlassian Crowd before 2.8.8 and 2.9.x before 2.9.5 allows remote attackers to execute arbitrary code via an LDAP attribute with a crafted serialized Java object, aka LDAP entry poisoning.
Affected Software
3 affected components
Atlassian crowd<=2.8.4
Atlassian crowd=2.9.0
Atlassian crowd=2.9.1
Event History
Dec 9, 2016
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-6496?
CVE-2016-6496 is classified as high severity due to the potential for remote code execution.
2
How do I fix CVE-2016-6496?
To fix CVE-2016-6496, upgrade to Atlassian Crowd versions 2.8.8 or 2.9.5 and later.
3
What types of attacks are possible with CVE-2016-6496?
CVE-2016-6496 allows remote attackers to execute arbitrary code through LDAP entry poisoning.
4
Which versions of Atlassian Crowd are affected by CVE-2016-6496?
Atlassian Crowd versions prior to 2.8.8 and 2.9.0 through 2.9.1 are affected by CVE-2016-6496.
5
Is CVE-2016-6496 exploitable without authentication?
Yes, CVE-2016-6496 can be exploited without authentication, making it a critical vulnerability.