Lucene search

K
cve[email protected]CVE-2014-0111
HistoryApr 17, 2014 - 2:55 p.m.

CVE-2014-0111

2014-04-1714:55:06
CWE-94
web.nvd.nist.gov
17
cve-2014-0111
apache syncope
remote code execution
apache commons jexl
security vulnerability

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

7.6 High

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

62.3%

Apache Syncope 1.0.0 before 1.0.9 and 1.1.0 before 1.1.7 allows remote administrators to execute arbitrary Java code via vectors related to Apache Commons JEXL expressions, “derived schema definition,” “user / role templates,” and “account links of resource mappings.”

Affected configurations

NVD
Node
apachesyncopeRange1.0.01.0.9
OR
apachesyncopeRange1.1.01.1.7

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

7.6 High

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

62.3%