Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Alexander Mirosh

Researcher fromHPE Security Fortify
#24696of 53,639
9.8Total CVSS
Vulnerabilities · 1
PT-2016-6956
9.8
2016-12-09
Atlassian · Crowd · CVE-2016-6496
**Name of the Vulnerable Software and Affected Versions** Atlassian Crowd versions prior to 2.8.8 Atlassian Crowd versions 2.9.x prior to 2.9.5 **Description** The issue allows remote attackers to execute arbitrary code via an LDAP attribute with a crafted serialized Java object. This is related to the LDAP directory connector in Atlassian Crowd. **Recommendations** For versions prior to 2.8.8, update to version 2.8.8 or later. For versions 2.9.x prior to 2.9.5, update to version 2.9.5 or later.