PT-2018-11701 · Apache · Apache Syncope

Publicado

2018-03-20

·

Atualizado

2019-03-08

·

CVE-2018-1322

CVSS v3.1

4.9

Média

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Syncope versions 1.0.x through 1.2.10 Apache Syncope versions 2.0.x through 2.0.7
Description An administrator with user search entitlements can recover sensitive security values using the fiql and orderby parameters.
Recommendations For Apache Syncope versions 1.0.x through 1.2.10, update to version 1.2.11 or later. For Apache Syncope versions 2.0.x through 2.0.7, update to version 2.0.8 or later.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-1322
GHSA-V3VF-2R98-XW8W

Produtos afetados

Apache Syncope