CVE-2014-0111: Code Injection
Apache Syncope 1.0.0 before 1.0.9 and 1.1.0 before 1.1.7 allows remote administrators to execute arbitrary Java code via vectors related to Apache Commons JEXL expressions, "derived schema definition," "user / role templates," and "account links of resource mappings."
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.apache.syncope:syncopeto a version that resolves this vulnerability.Fixed in 1.1.7 - Upgrade
Upgrade
maven/org.apache.syncope:syncopeto a version that resolves this vulnerability.Fixed in 1.0.9
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0111?
CVE-2014-0111 has a severity rating of important, allowing remote code execution by unauthorized users.
How do I fix CVE-2014-0111?
To fix CVE-2014-0111, upgrade Apache Syncope to version 1.0.9 or 1.1.7 or later.
What versions of Apache Syncope are affected by CVE-2014-0111?
CVE-2014-0111 affects Apache Syncope versions prior to 1.0.9 and versions prior to 1.1.7.
What type of attacks does CVE-2014-0111 enable?
CVE-2014-0111 enables remote administrators to execute arbitrary Java code via specific JEXL expression vulnerabilities.
Is CVE-2014-0111 a local or remote vulnerability?
CVE-2014-0111 is a remote vulnerability that allows unauthorized users to exploit the system.