Impact
An administrator with sufficient privileges can cause an unfiltered SQL query to be executed by the Apache Syncope application. The flaw originates from unsanitized entityKey and opEvent parameters that are used in the Audit Events search functionality, enabling an attacker to inject arbitrary SQL statements. This can lead to data disclosure, manipulation of database contents, or further exploitation of the underlying database. The vulnerability is categorized as CWE-89, a classic SQL injection weakness.
Affected Systems
The flaw exists in Apache Syncope versions from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, and from 4.1.0-M0 through 4.1.2. The vendor is Apache Software Foundation’s Apache Syncope. Users of these versions should upgrade to at least 4.0.8 or 4.1.3 to apply the fix.
Risk and Exploitability
The CVSS score of 9.8 indicates high severity. The vulnerability requires an attacker to have access to an account with administrator privileges, therefore the attack surface is limited to insiders or compromised credential scenarios. The EPSS score is less than 1%, and the vulnerability is not listed in the CISA KEV catalog. However, the nature of the flaw allows execution of stacked queries, which could provide attackers with significant data manipulation or exfiltration capabilities.
OpenCVE Enrichment