First published: Fri Feb 03 2017(Updated: )
Unspecified methods in the RACF Connector component before 1.1.1.0 in ForgeRock OpenIDM and OpenICF improperly call the SearchControls constructor with returnObjFlag set to true, which allows remote attackers to execute arbitrary code via a crafted serialized Java object, aka LDAP entry poisoning.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Forgerock Racf Connector | <=1.1.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6500 has a high severity rating due to its potential for remote code execution.
To fix CVE-2016-6500, upgrade the ForgeRock RACF Connector to version 1.1.1.0 or later.
CVE-2016-6500 affects versions of ForgeRock RACF Connector prior to 1.1.1.0.
CVE-2016-6500 may allow remote attackers to execute arbitrary code through LDAP entry poisoning.
While CVE-2016-6500 is known, its actual exploitation in the wild may vary.