com.sap.scimono:scimono-server@0.0.8 vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the com.sap.scimono:scimono-server package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Information Exposure

com.sap.scimono:scimono-server is an Open source SCIM 2.0 client and server library.

Affected versions of this package are vulnerable to Information Exposure. Due to improper input sanitization, specially crafted LDAP queries can be injected by an unauthenticated user. This could partially impact the confidentiality of the application.

How to fix Information Exposure?

Upgrade com.sap.scimono:scimono-server to version 0.0.23 or higher.

[,0.0.23)
  • H
Remote Code Execution (RCE)

com.sap.scimono:scimono-server is an Open source SCIM 2.0 client and server library.

Affected versions of this package are vulnerable to Remote Code Execution (RCE). An attacker could inject and execute java expression and compromising the availability and integrity of the system.

How to fix Remote Code Execution (RCE)?

Upgrade com.sap.scimono:scimono-server to version 0.0.19 or higher.

[,0.0.19)