CVE-2016-6496: Atlassian Crowd
Critical severity, CVSS 9.8. EPSS: 4.7% chance of exploitation in the next 30 days.
The LDAP directory connector in Atlassian Crowd before 2.8.8 and 2.9.x before 2.9.5 allows remote attackers to execute arbitrary code via an LDAP attribute with a crafted serialized Java object, aka LDAP entry poisoning.
Affected products
- Atlassian Crowd: up to and including 2.8.4; version 2.9.0 only; version 2.9.1 only
Published 2016-12-09. Last modified 2026-06-17.