Apache Syncope
- >= 3.0.0-M0, <= 3.0.16
- >= 4.0.0-M0, <= 4.0.6
- >= 4.1.0-M0, <= 4.1.1
A SQL injection vulnerability has been identified in Apache Syncope versions 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.6, and 4.1.0-M0 through 4.1.1. This vulnerability allows an administrator with the appropriate entitlements to execute arbitrary SQL by using stacked queries, taking advantage of unsanitized sort parameters.
Exploitation of this vulnerability allows for arbitrary SQL execution, which could lead to unauthorized data access or manipulation.
Users are advised to upgrade to Apache Syncope version 4.0.7 or 4.1.2, both of which address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.