Impact
An administrator with adequate entitlements can achievecope’s connector subsystem by exploiting Groovy scripts in scripted connectors such as REST and SQL. The vulnerability is due to improper isolation or compartmentalization, allowing arbitrary code execution under the privileges of the authenticated user. This weakness is identified as CWE-653, which involves failure to restrict the use of a function or library to a safe domain.
Affected Systems
Apache Syncope versions from 3.0.0‑M0 through 3.0.16, from 4.0.0‑M0 through 4.0.6, and from 4.1.0‑M0 through 4.1.1 are affected. The product is provided by the Apache Software Foundation.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in KEV. Because remote code execution is possible, the risk remains high, especially when an attacker can obtain administrative privileges. The CVSS score is 9.8. Attacks would require exploitation of the scripted connector functionality, which may be triggered remotely through the connector API.
OpenCVE Enrichment