CVE-2016-6501: JFrog Artifactory

Critical severity, CVSS 9.8. EPSS: 3.9% chance of exploitation in the next 30 days.

JFrog Artifactory before 4.11 allows remote attackers to execute arbitrary code via an LDAP attribute with a crafted serialized Java object, aka LDAP entry poisoning.

Affected products

  • JFrog Artifactory: up to and including 4.10

Published 2016-12-09. Last modified 2026-06-17.