CVE Vulnerabilities

CVE-2014-3503

Published: Jul 11, 2014 | Modified: Oct 09, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Apache Syncope 1.1.x before 1.1.8 uses weak random values to generate passwords, which makes it easier for remote attackers to guess the password via a brute force attack.

Affected Software

Name Vendor Start Version End Version
Syncope Apache 1.1.6 1.1.6
Syncope Apache 1.1.3 1.1.3
Syncope Apache 1.1.1 1.1.1
Syncope Apache 1.1.5 1.1.5
Syncope Apache 1.1.0 1.1.0
Syncope Apache 1.1.2 1.1.2
Syncope Apache 1.1.4 1.1.4
Syncope Apache 1.1.7 1.1.7

References