Impact
An administrator with sufficient privileges can cause an unfiltered SQL query to be executed by the Apache Syncope application. The flaw originates from unsanitKey and opEvent that are used in the Audit Events search functionality, enabling an attacker to inject arbitrary SQL statements. This can lead to data disclosure, modification of database contents, or further exploitation of the underlying database. The vulnerability is categorized as CWE-89, a classic SQL injection weakness.
Affected Systems
The flaw exists in Apache Syncope across the following0 through 3.0.16, version 4.0.0-M0 through 4.0.7, and version 4.1.0-M0 through 4.1.2. The vendors affected are the Apache Software Foundation’s Apache Syncope product. Users of these versions are advised to upgrade to at least 4.0.8 or 4.1.3, which contain the necessary fix.
Risk and Exploitability
The vulnerability requires an attacker to have access to an account with administrator privileges, therefore the attack surface is limited to insiders or compromised credential scenarios. No publicly disclosed exploit score (EPSS) is available, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. However, the nature of the flaw allows execution of stacked queries, which could provide attackers with significant data manipulation or exfiltration capabilities.
OpenCVE Enrichment