CVE-2014-0111

Apache Syncope 1.0.0-1.0.8 and 1.1.0-1.1.6 - Authenticated Remote Code Execution via JEXL Expression Injection

Title source: llm
STIX 2.1

Description

Apache Syncope 1.0.0 before 1.0.9 and 1.1.0 before 1.1.7 allows remote administrators to execute arbitrary Java code via vectors related to Apache Commons JEXL expressions, "derived schema definition," "user / role templates," and "account links of resource mappings."

References (3)

Core 3
Core References
Vendor Advisory x_refsource_confirm
http://syncope.apache.org/security.html
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/531841/100/0/threaded

Scores

EPSS 0.0142
EPSS Percentile 80.9%

Details

CWE
CWE-94
Status published
Products (2)
apache/syncope 1.0.0 - 1.0.9
org.apache.syncope/syncope 1.0.0 - 1.0.9Maven
Published Apr 17, 2014
Tracked Since Feb 18, 2026