Security Advisory
CVE-2016-6496
9.8
CRITICAL
Vulnerability Description
The LDAP directory connector in Atlassian Crowd before 2.8.8 and 2.9.x before 2.9.5 allows remote attackers to execute arbitrary code via an LDAP attribute with a crafted serialized Java object, aka LDAP entry poisoning.
Published Date
December 9, 2016
Official Source
NIST NVD Advisory