VYPR

Syncope

by Apache

Source repositories

CVEs (24)

  • CVE-2026-53421CriJul 20, 2026
    risk 0.00cvss 9.8epss 0.01

    Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve remote code execution through the connector subsystem by relying on scripted connectors' (REST and SQL) capability to run Groovy scripts. This…

  • CVE-2026-53405CriJul 20, 2026
    risk 0.00cvss 9.8epss 0.00

    Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can import arbitrary BPMN process definitions via the REST API and then start the process. When a BPMN process containing a Groovy scriptTask is imported…

  • CVE-2014-3503Jul 11, 2014
    risk 0.00cvss epss 0.06

    Apache Syncope 1.1.x before 1.1.8 uses weak random values to generate passwords, which makes it easier for remote attackers to guess the password via a brute force attack.

  • CVE-2014-0111Apr 17, 2014
    risk 0.00cvss epss 0.03

    Apache Syncope 1.0.0 before 1.0.9 and 1.1.0 before 1.1.7 allows remote administrators to execute arbitrary Java code via vectors related to Apache Commons JEXL expressions, "derived schema definition," "user / role templates," and "account links of resource mappings."

Page 2 of 2