← Vulnerability feed

Vulnerability record · CVE-2016-8750 · published 19 February 2018

CVE-2016-8750: Apache karaf ldap injection vulnerability

Apache · Karaf

Apache Karaf prior to 4.0.8 used the LDAPLoginModule to authenticate users to a directory via LDAP. However, it did not encoding usernames properly and hence was vulnerable to LDAP injection attacks leading to a denial of service.

6.5 CVSS 3.0 Medium EPSS 5.2% · top 7.8% CWE-90 · LDAP injection
6.5CVSS 3.0 base score, v2 4.0
5.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Apache Karaf prior to 4.0.8 used the LDAPLoginModule to authenticate users to a directory via LDAP. However, it did not encoding usernames properly and hence was vulnerable to LDAP injection attacks leading to a denial of service.

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-8750 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-40145Apache karaf improper input validation vulnerabilityThis vulnerable is about a potential code injection when an attacker has control of the target LDAP server using in the JDBC JNDI URL. The function j…EPSS 2.4%9.8CVE-2018-11788Apache karaf xml external entity (xxe) vulnerabilityApache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by dropping the file directly in the deploy folder. The …EPSS 7.3%8.8CVE-2018-11786Apache karaf improper privilege management vulnerabilityIn Apache Karaf prior to 4.2.0 release, if the sshd service in Karaf is left on so an administrator can manage the running instance, any user with ri…EPSS 1.9%8.1CVE-2021-41766Apache karaf deserialization of untrusted data vulnerabilityApache Karaf allows monitoring of applications and the Java runtime by using the Java Management Extensions (JMX). JMX is a Java RMI based technology…EPSS 2.0%8.1CVE-2020-28052Bouncycastle bc-java vulnerabilityAn issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data …EPSS 7.2%8.1CVE-2018-11787Apache karaf improper authentication vulnerabilityIn Apache Karaf version prior to 3.0.9, 4.0.9, 4.1.1, when the webconsole feature is installed in Karaf, it is available at .../system/console and re…EPSS 2.6%6.5CVE-2019-0191Apache karaf path traversal vulnerabilityApache Karaf kar deployer reads .kar archives and extracts the paths from the "repository/" and "resources/" entries in the zip file. It then writes …EPSS 4.9%6.3CVE-2020-11980Apache karaf server-side request forgery (ssrf) vulnerabilityIn Karaf, JMX authentication takes place using JAAS and authorization takes place using ACL files. By default, only an "admin" can actually invoke on…EPSS 1.9%

Source: NIST National Vulnerability Database (record CVE-2016-8750), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.