Impact
This vulnerability is a Cypher injection flaw in the Neo4j persistence layer of Apache Syncope. The flaw is triggered by certain FIQL search conditions that are not properly sanitized. An attacker who can supply a crafted FIQL query could inject and execute arbitrary Cypher statements, potentially reading, modifying, or deleting data stored in Neo4j. The weakness aligns with CWE‑89, which governs injection attacks that enable execution of unintended commands.
Affected Systems
Apache Syncope versions 3.0.0‑M0 through 3.0.16, 4.0.0‑M0 through 4.0.7, and 4.1.0‑M0 through 4.1.2 are affected. Upgrade to 4.0.8 or 4.1.3 eliminates the vulnerability.
Risk and Exploitability
The CVSS score indicates a high severity of 9.8, while the EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote API or web endpoint that accepts FIQL search parameters, allowing an unauthenticated or authenticated attacker to inject malicious Cypher statements if they can submit the query. Because the injection can execute arbitrary Cypher, the impact may be total loss of data confidentiality, integrity, and availability. The low EPSS score suggests exploitation is not yet widespread, but the high CVSS score warrants immediate attention, especially if the FIQL endpoint is exposed.
OpenCVE Enrichment