syncope-ext-flowable-bpmn is vulnerable to arbitrary code execution. An administrator with workflow entitlements can use Shell Service Tasks to perform arbitrary code execution when the Flowable extension is enabled.
CPE | Name | Operator | Version |
---|---|---|---|
apache syncope ext: flowable bpmn | le | 2.1.6 |