Remote Code Execution Vulnerability in Apache Syncope by Apache
CVE-2020-11977
7.2HIGH
What is CVE-2020-11977?
In Apache Syncope versions prior to 2.1.7, the Flowable extension can be exploited by administrators with proper workflow entitlements. This vulnerability enables performing unauthorized operations through Shell Service Tasks, which include file reading, file writing, and executing arbitrary code. Such actions pose a significant risk to the integrity and confidentiality of the system and its data.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Apache Syncope Apache Syncope 2.1.X releases prior to 2.1.7
References
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved