AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2016-6500

HIGH · CVSS 8.1 EPSS 2.28%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2017-02-03 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2016-6500
Severity
HIGH
CVSS
8.1
EPSS
2.28%
Java

Original NVD Description

Unspecified methods in the RACF Connector component before 1.1.1.0 in ForgeRock OpenIDM and OpenICF improperly call the SearchControls constructor with returnObjFlag set to true, which allows remote attackers to execute arbitrary code via a crafted serialized Java object, aka LDAP entry poisoning.