CVE-2014-3503: Apache Syncope
Medium severity, CVSS 5.0. EPSS: 6% chance of exploitation in the next 30 days.
Apache Syncope 1.1.x before 1.1.8 uses weak random values to generate passwords, which makes it easier for remote attackers to guess the password via a brute force attack.
Affected products
- Apache Syncope: version 1.1.0 only; version 1.1.1 only; version 1.1.2 only; version 1.1.3 only; version 1.1.4 only; version 1.1.5 only; …
Published 2014-07-11. Last modified 2026-06-17.