Vulnerabilities (CVE)

Filtered by vendor Apache Subscribe
Filtered by product Syncope
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-0111 1 Apache 1 Syncope 2019-03-21 6.5 MEDIUM N/A
Apache Syncope 1.0.0 before 1.0.9 and 1.1.0 before 1.1.7 allows remote administrators to execute arbitrary Java code via vectors related to Apache Commons JEXL expressions, "derived schema definition," "user / role templates," and "account links of resource mappings."
CVE-2014-3503 1 Apache 1 Syncope 2018-10-09 5.0 MEDIUM N/A
Apache Syncope 1.1.x before 1.1.8 uses weak random values to generate passwords, which makes it easier for remote attackers to guess the password via a brute force attack.