CVE-2014-3503

Currently unrated

Key Information:

Vendor
Apache
Status
Vendor
CVE Published:
11 July 2014

Summary

Apache Syncope 1.1.x before 1.1.8 uses weak random values to generate passwords, which makes it easier for remote attackers to guess the password via a brute force attack.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.