Security Advisory

CVE-2016-6496

9.8
CRITICAL

Vulnerability Description

The LDAP directory connector in Atlassian Crowd before 2.8.8 and 2.9.x before 2.9.5 allows remote attackers to execute arbitrary code via an LDAP attribute with a crafted serialized Java object, aka LDAP entry poisoning.
Published Date December 9, 2016
Official Source NIST NVD Advisory