📦

racf_connector

Vendor: forgerock

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 1 Remote Access
Total CVEs 18 Total Indexed
Avg. EPSS 2.28% Exploit Prob.
Latest CVE CVE-2016-6500 Feb 03

Security Vulnerability Index

Page 1 / 2
8.1 CVSS

Unspecified methods in the RACF Connector component before 1.1.1.0 in ForgeRock OpenIDM and OpenICF improperly call the SearchControls constructor with returnObjFlag set to true, which allows remote attackers to execute arbitrary code via a crafted serialized Java object, aka LDAP entry poisoning.

EPSS: 2.28%