CVE-2016-6497: Apache Groovy LDAP
High severity, CVSS 7.5. EPSS: 5.7% chance of exploitation in the next 30 days.
main/java/org/apache/directory/groovyldap/LDAP.java in the Groovy LDAP API in Apache allows attackers to conduct LDAP entry poisoning attacks by leveraging setting returnObjFlag to true for all search methods.
Affected products
- Apache Groovy LDAP: any version
Published 2017-01-18. Last modified 2026-06-17.