CVE-2016-6497: Apache Groovy LDAP

High severity, CVSS 7.5. EPSS: 5.7% chance of exploitation in the next 30 days.

main/java/org/apache/directory/groovyldap/LDAP.java in the Groovy LDAP API in Apache allows attackers to conduct LDAP entry poisoning attacks by leveraging setting returnObjFlag to true for all search methods.

Affected products

  • Apache Groovy LDAP: any version

Published 2017-01-18. Last modified 2026-06-17.