Apache

Syncope

46 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.29%
  • Veröffentlicht 14.09.2026 13:24:22
  • Zuletzt bearbeitet 14.09.2026 20:58:48

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Syncope. When the Syncope SRA is configured for CAS authentication, the target Apereo CAS instance's URL is calculated by unconditionally looking at client-supplied forw...

  • EPSS 0.34%
  • Veröffentlicht 14.09.2026 13:23:47
  • Zuletzt bearbeitet 14.09.2026 20:58:48

Improper Encoding or Escaping of Output vulnerability in Apache Syncope. Authenticated users can store a spreadsheet formula payload in one of their own plain attributes. When such users are included in a CSV export and the generated CSV file is o...

  • EPSS 0.34%
  • Veröffentlicht 14.09.2026 13:23:17
  • Zuletzt bearbeitet 14.09.2026 20:58:48

Incorrect Authorization vulnerability in Apache Syncope. Delegated administration security checks are based on Realm hierarchy and enforced via prefix matches. Due to incorrect implementation, two sibling Realms whose names begin with the same str...

  • EPSS 0.48%
  • Veröffentlicht 14.09.2026 13:07:58
  • Zuletzt bearbeitet 14.09.2026 20:58:48

Incorrect Authorization vulnerability in Apache Syncope. Delegated administration security checks performed by Reconciliation service's pull and push, being incomplete, could accept calls by administrator not provided with adequate entitlements. ...

Medienbericht
  • EPSS 0.41%
  • Veröffentlicht 14.09.2026 13:06:19
  • Zuletzt bearbeitet 14.09.2026 20:58:48

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Syncope. An administrator with adequate entitlements can get access via REST to the list of existing Access Tokens, including their signed JWT body. These values can ...

  • EPSS 0.48%
  • Veröffentlicht 14.09.2026 12:58:51
  • Zuletzt bearbeitet 14.09.2026 20:58:48

Improper Privilege Management vulnerability in Apache Syncope. Delegations can be created or updated with Roles not owned by the delegating User, or not for the same Realm subtree under the delegation management was granted for. This issue af...

  • EPSS 0.48%
  • Veröffentlicht 14.09.2026 12:56:31
  • Zuletzt bearbeitet 14.09.2026 20:58:48

Incorrect Authorization vulnerability in Apache Syncope. Any search requests are transformed into SQL, Neo4J or Elasticsearch / Opensearch queries, depending on the actual deployment configuration. An important component of such transformation is ...

  • EPSS 0.38%
  • Veröffentlicht 14.09.2026 12:55:27
  • Zuletzt bearbeitet 14.09.2026 20:58:48

Insufficiently Protected Credentials vulnerability in Apache Syncope. Audit events, when sent to the configured store, are not sufficiently masked for the sensitive values they might carry on their payloads, thus allowing administrators to access su...

  • EPSS 0.58%
  • Veröffentlicht 14.09.2026 12:54:22
  • Zuletzt bearbeitet 14.09.2026 20:58:48

Missing Authorization vulnerability in Apache Syncope. An administrator with task execution entitlements might be able to mass (de)provision group members, regardless of their group-related administration capabilities. This issue affects Apac...

  • EPSS 0.56%
  • Veröffentlicht 14.09.2026 12:52:49
  • Zuletzt bearbeitet 14.09.2026 20:58:48

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging unsanitized ...