Apache Syncope CVE-2018-1321 Multiple Remote Code Execution Vulnerabilities
BID:103508
CVE-2018-1321 |Info
Apache Syncope CVE-2018-1321 Multiple Remote Code Execution Vulnerabilities
| Bugtraq ID: | 103508 |
| Class: | Design Error |
| CVE: |
CVE-2018-1321 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 20 2018 12:00AM |
| Updated: | Mar 20 2018 12:00AM |
| Credit: | The vendor reported these issues. |
| Vulnerable: |
Apache Syncope 2.0.7 Apache Syncope 2.0 Apache Syncope 1.2.10 Apache Syncope 1.1.8 Apache Syncope 1.1.7 Apache Syncope 1.1.6 Apache Syncope 1.1.5 Apache Syncope 1.1.4 Apache Syncope 1.1.3 Apache Syncope 1.1.2 Apache Syncope 1.1.1 Apache Syncope 1.1.0 Apache Syncope 1.0.9 Apache Syncope 1.0.8 Apache Syncope 1.0.0 |
| Not Vulnerable: |
Apache Syncope 2.0.8 Apache Syncope 1.2.11 |
Discussion
Apache Syncope CVE-2018-1321 Multiple Remote Code Execution Vulnerabilities
Apache Syncope is prone to multiple remote code execution vulnerabilities.
Successfully exploiting this issue allows attackers to execute arbitrary code in the context of the affected application.
Apache Syncope versions prior to 1.2.11 and prior to 2.0.8 are vulnerable.
Apache Syncope is prone to multiple remote code execution vulnerabilities.
Successfully exploiting this issue allows attackers to execute arbitrary code in the context of the affected application.
Apache Syncope versions prior to 1.2.11 and prior to 2.0.8 are vulnerable.
Exploit / POC
Apache Syncope CVE-2018-1321 Multiple Remote Code Execution Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Apache Syncope CVE-2018-1321 Multiple Remote Code Execution Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Apache Syncope CVE-2018-1321 Multiple Remote Code Execution Vulnerabilities
References:
References:
- Apache Syncope (Apache Software Foundation)
- Security Advisories (Apache)