PT-2018-11701 · Apache · Apache Syncope

Published

2018-03-20

·

Updated

2019-03-08

·

CVE-2018-1322

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Syncope versions 1.0.x through 1.2.10 Apache Syncope versions 2.0.x through 2.0.7
Description An administrator with user search entitlements can recover sensitive security values using the fiql and orderby parameters.
Recommendations For Apache Syncope versions 1.0.x through 1.2.10, update to version 1.2.11 or later. For Apache Syncope versions 2.0.x through 2.0.7, update to version 2.0.8 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1322
GHSA-V3VF-2R98-XW8W

Affected Products

Apache Syncope