PT-2014-3482 · Apache · Apache Syncope+1

Publicado

2014-04-17

·

Atualizado

2022-05-14

·

CVE-2014-0111

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Apache Syncope versions 1.0.0 through 1.0.8 Apache Syncope versions 1.1.0 through 1.1.6
Description The issue allows remote administrators to execute arbitrary Java code via vectors related to Apache Commons JEXL expressions, derived schema definition, user/role templates, and account links of resource mappings.
Recommendations For Apache Syncope versions 1.0.0 through 1.0.8, update to version 1.0.9 or later. For Apache Syncope versions 1.1.0 through 1.1.6, update to version 1.1.7 or later.

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-0111
GHSA-R2XF-W5PJ-9PW8

Produtos afetados

Apache Commons Jelly
Apache Syncope