Remote Code Execution Vulnerability in Apache Syncope by Apache
CVE-2020-11977
7.2HIGH
Summary
In Apache Syncope versions prior to 2.1.7, the Flowable extension can be exploited by administrators with proper workflow entitlements. This vulnerability enables performing unauthorized operations through Shell Service Tasks, which include file reading, file writing, and executing arbitrary code. Such actions pose a significant risk to the integrity and confidentiality of the system and its data.
Affected Version(s)
Apache Syncope Apache Syncope 2.1.X releases prior to 2.1.7
References
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved