CVE Vulnerabilities

CVE-2014-3503

Published: Jul 11, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Apache Syncope 1.1.x before 1.1.8 uses weak random values to generate passwords, which makes it easier for remote attackers to guess the password via a brute force attack.

Affected Software

NameVendorStart VersionEnd Version
SyncopeApache1.1.0 (including)1.1.0 (including)
SyncopeApache1.1.1 (including)1.1.1 (including)
SyncopeApache1.1.2 (including)1.1.2 (including)
SyncopeApache1.1.3 (including)1.1.3 (including)
SyncopeApache1.1.4 (including)1.1.4 (including)
SyncopeApache1.1.5 (including)1.1.5 (including)
SyncopeApache1.1.6 (including)1.1.6 (including)
SyncopeApache1.1.7 (including)1.1.7 (including)

References