- Description
- Apache Syncope can be configured to store the user password values in the internal database with AES encryption, though this is not the default option. When AES is configured, the default key value, hard-coded in the source code, is always used. This allows a malicious attacker, once obtained access to the internal database content, to reconstruct the original cleartext password values. This is not affecting encrypted plain attributes, whose values are also stored using AES encryption. Users are recommended to upgrade to version 3.0.15 / 4.0.3, which fix this issue.
- Source
- security@apache.org
- NVD status
- Analyzed
- Products
- syncope
CVSS 3.1
- Type
- Secondary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity
- HIGH
- security@apache.org
- CWE-321
- Hype score
- Not currently trending
Apache Syncope で危険度の高い脆弱性(CVE-2025-65998) https://t.co/IGPFf5Xt9R #セキュリティ対策Lab #セキュリティ #Security
@securityLab_jp
1 Dec 2025
94 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Warning: CVE-2025-65998 CVSS:7.5 is a vulnerability in #Apache #Syncope, enabling attackers to decrypt user passwords by stealing a hard-coded default encryption key. RedHat suggests upgrading to version 3.0.15 / 4.0.3, more info at: https://t.co/K9YT7jSY2K. #Patch #Patch #Patch
@CCBalert
27 Nov 2025
204 Impressions
2 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔍 𝐀𝐩𝐚𝐜𝐡𝐞 𝐒𝐲𝐧𝐜𝐨𝐩𝐞 𝐅𝐥𝐚𝐰 𝐄𝐱𝐩𝐨𝐬𝐞𝐬 𝐈𝐧𝐭𝐞𝐫𝐧𝐚𝐥 𝐃𝐚𝐭𝐚𝐛𝐚𝐬𝐞 𝐃𝐚𝐭𝐚 • Apache Syncope has a vulnerability that exposes data when using AES password encryptio
@PurpleOps_io
27 Nov 2025
51 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Critical vulnerabilities unveiled: Apache Syncope’s CVE-2025-65998 risks stored passwords; Fluent Bit RCE flaws enable cloud attacks; Oracle KEV exploits affect Canon; major breaches hit Dartmouth, SitusAMC, Almaviva, and more. #DataBreach #CloudSecurity https://t.co/aHIFKrnnGJ
@TweetThreatNews
26 Nov 2025
171 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-65998 Apache Syncope can be configured to store the user password values in the internal database with AES encryption, though this is not the default option. When AES is c… https://t.co/QEMNMfnuNA
@CVEnew
24 Nov 2025
192 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apache:syncope:*:*:*:*:*:*:*:*",
"matchCriteriaId": "D773E581-822F-4431-BEFB-48BE61A743EC",
"versionEndIncluding": "2.1.14",
"versionStartIncluding": "2.1.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:apache:syncope:*:*:*:*:*:*:*:*",
"matchCriteriaId": "DE40E959-C93C-43E0-80AE-4FAB31C47165",
"versionEndExcluding": "3.0.15",
"versionStartIncluding": "3.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:apache:syncope:*:*:*:*:*:*:*:*",
"matchCriteriaId": "EFD9390D-0F3F-453D-ACCC-BFF74C6D9623",
"versionEndExcluding": "4.0.3",
"versionStartIncluding": "4.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]