PatchSiren cyber security CVE debrief
CVE-2016-6497 Apache CVE debrief
CVE-2016-6497 is a high-severity LDAP integrity issue in Apache’s Groovy LDAP API. NVD describes it as an LDAP entry poisoning weakness caused by setting `returnObjFlag` to true for all search methods in `LDAP.java`. In practice, that means applications using the affected component may accept LDAP results in a way that can be manipulated by an attacker over the network, with the primary impact being data integrity rather than confidentiality or availability.
- Vendor
- Apache
- Product
- Groovy Ldap
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-18
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-18
- Advisory updated
- 2026-05-13
Who should care
Security teams, Java application owners, and developers who use or embed Apache Groovy LDAP API components should review this CVE. It is especially relevant for systems that perform LDAP searches and trust returned objects or directory content. Because the vulnerability is network-reachable and requires no privileges or user interaction, exposed applications should be prioritized.
Technical summary
NVD maps the issue to `cpe:2.3:a:apache:groovy_ldap:*:*:*:*:*:*:*:*` and rates it CVSS 3.1 7.5 HIGH (`AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N`). The described flaw is in `main/java/org/apache/directory/groovyldap/LDAP.java`, where `returnObjFlag` is set to true for all search methods. That behavior can allow LDAP entry poisoning, which NVD classifies under CWE-254. The supplied references include an Apache mailing list thread, a patch diff, and a technical paper that provide additional context for the issue.
Defensive priority
High. The vulnerability is remotely reachable, requires no authentication, and has a high integrity impact. Systems that expose LDAP search functionality or rely on object-returning LDAP responses should be reviewed promptly.
Recommended defensive actions
- Inventory any use of Apache Groovy LDAP API or embedded copies of `org.apache.directory.groovyldap`.
- Apply the vendor or upstream patch referenced in the Apache SVN diff, or upgrade to a fixed release if one is available in your environment.
- Review application code that consumes LDAP search results and avoid relying on object-returning behavior unless it is explicitly required and trusted.
- Restrict or segment LDAP access so only expected internal clients can reach affected services.
- Validate directory inputs and monitor for unexpected LDAP entries or response patterns consistent with poisoning attempts.
- If this component is present in a larger product, check downstream vendor advisories and patch guidance for that product line.
Evidence notes
This debrief is based only on the supplied NVD record and linked references. The NVD entry provides the official CVSS vector, affected CPE, and weakness classification. The Apache SVN patch reference and Apache mailing list link support the issue description, while the Black Hat paper gives broader technical context for LDAP/JNDI manipulation. No exploit code or unsupported remediation details are included.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-6497 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-6497
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-6497 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-6497
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://mail-archives.apache.org/mod_mbox/directory-users/201610.mbox/%3Cb7d7e909-a8ed-1ab4-c853-4078c1e7624a%40stefan-seelmann.de%3E
[email protected] - Mailing List, Third Party Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.blackhat.com/docs/us-16/materials/us-16-Munoz-A-Journey-From-JNDI-LDAP-Manipulation-To-RCE-wp.pdf
[email protected] - Technical Description, Third Party Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
[email protected] - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.