Security Advisory
CVE-2014-3503
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
Apache Syncope 1.1.x before 1.1.8 uses weak random values to generate passwords, which makes it easier for remote attackers to guess the password via a brute force attack.