CVE

Id
93320  
CVE No.
CVE-2016-6500  
Status
Candidate  
Description
Unspecified methods in the RACF Connector component before 1.1.1.0 in ForgeRock OpenIDM and OpenICF improperly call the SearchControls constructor with returnObjFlag set to true, which allows remote attackers to execute arbitrary code via a crafted serialized Java object, aka LDAP entry poisoning.  
Phase
Assigned (20160801)  
Votes
None (candidate not yet proposed)  
Comments