CVE-2016-6501: Input Validation
Published Dec 9, 2016
·Updated
JFrog Artifactory before 4.11 allows remote attackers to execute arbitrary code via an LDAP attribute with a crafted serialized Java object, aka LDAP entry poisoning.
Affected Software
1 affected component
JFrog Artifactory<=4.10
Event History
Dec 9, 2016
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-6501?
CVE-2016-6501 is classified as a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2016-6501?
To fix CVE-2016-6501, upgrade JFrog Artifactory to version 4.11 or later.
3
What software is affected by CVE-2016-6501?
CVE-2016-6501 affects JFrog Artifactory versions prior to 4.11.
4
What type of attack does CVE-2016-6501 enable?
CVE-2016-6501 enables remote attackers to execute arbitrary code through LDAP entry poisoning.
5
Is CVE-2016-6501 a local or remote vulnerability?
CVE-2016-6501 is a remote vulnerability that allows exploitation from an external attacker.