Apache

Syncope

46 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.51%
  • Veröffentlicht 14.09.2026 10:38:12
  • Zuletzt bearbeitet 14.09.2026 20:58:48

Authentication bypass by spoofing vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can spoof another user's privileges after completing a succ...

  • EPSS 0.26%
  • Veröffentlicht 14.09.2026 10:22:29
  • Zuletzt bearbeitet 14.09.2026 20:58:48

Improper verification of cryptographic signature vulnerability in Apache Syncope. When SRA is configured for OAuth 2.0 without JWKS set URI assigned, an attacker can forge arbitrary JWTs to impersonate any user identity and permissions, gaining fu...

  • EPSS 0.3%
  • Veröffentlicht 20.07.2026 14:27:04
  • Zuletzt bearbeitet 27.07.2026 14:58:20

Low-privileged authenticated Server-Side Request Forgery (SSRF) vulnerability in Apache Syncope via Connectors and Resources check. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 throug...

  • EPSS 0.41%
  • Veröffentlicht 20.07.2026 14:23:20
  • Zuletzt bearbeitet 27.07.2026 14:59:50

Improper Privilege Management vulnerability in Apache Syncope. When: * the all-Java user workflow adapter is configured, or * the Flowable user workflow adapter is configured, bearing a BPMN definition not requiring admin approval for user self reg...

Medienbericht
  • EPSS 0.5%
  • Veröffentlicht 20.07.2026 14:21:57
  • Zuletzt bearbeitet 27.07.2026 15:00:04

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging unsanitized sort...

  • EPSS 0.68%
  • Veröffentlicht 20.07.2026 14:21:10
  • Zuletzt bearbeitet 27.07.2026 15:00:13

Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve remote code execution through the connector subsystem by relying on scripted connectors' (REST and SQL) capability ...

  • EPSS 0.45%
  • Veröffentlicht 20.07.2026 14:20:06
  • Zuletzt bearbeitet 27.07.2026 15:00:33

Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can import arbitrary BPMN process definitions via the REST API and then start the process. When a BPMN process containing a Groov...

  • EPSS 0.44%
  • Veröffentlicht 20.07.2026 14:19:19
  • Zuletzt bearbeitet 27.07.2026 14:58:11

Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code bypassing the Groovy security sandbox. This is...

  • EPSS 0.44%
  • Veröffentlicht 25.05.2026 15:00:55
  • Zuletzt bearbeitet 24.07.2026 10:10:00

Exposure of Sensitive Information Through Data Queries vulnerability in Apache Syncope. An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficient entitlement...

  • EPSS 0.65%
  • Veröffentlicht 25.05.2026 14:58:59
  • Zuletzt bearbeitet 24.07.2026 10:10:00

Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code reaching a non-sandboxed execution path via the...