Apache Syncope CVE-2014-0111 Remote Code Execution Vulnerability
BID:66927
Info
Apache Syncope CVE-2014-0111 Remote Code Execution Vulnerability
| Bugtraq ID: | 66927 |
| Class: | Design Error |
| CVE: |
CVE-2014-0111 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 16 2014 12:00AM |
| Updated: | Apr 16 2014 12:00AM |
| Credit: | Grégory Draperi |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Apache Syncope CVE-2014-0111 Remote Code Execution Vulnerability
Apache Syncope is prone to remote code execution vulnerability.
Successfully exploiting this issue allows attackers to execute arbitrary code in the context of the affected application.
The following versions are affected:
Apache Syncope 1.0.0 through 1.0.8
Apache Syncope 1.1.0 through 1.1.6
Apache Syncope is prone to remote code execution vulnerability.
Successfully exploiting this issue allows attackers to execute arbitrary code in the context of the affected application.
The following versions are affected:
Apache Syncope 1.0.0 through 1.0.8
Apache Syncope 1.1.0 through 1.1.6
Exploit / POC
Apache Syncope CVE-2014-0111 Remote Code Execution Vulnerability
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
Apache Syncope CVE-2014-0111 Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Apache Syncope CVE-2014-0111 Remote Code Execution Vulnerability
References:
References: