CVE-2018-1322

MEDIUM

Apache Syncope < 1.2.11 - Information Disclosure

Title source: rule

Description

An administrator with user search entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x which may be also affected, can recover sensitive security values using the fiql and orderby parameters.

Exploits (1)

exploitdb WORKING POC
by Che-Chun Kuo · textwebappswindows
https://www.exploit-db.com/exploits/45400

Scores

CVSS v3 4.9
EPSS 0.0673
EPSS Percentile 91.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-200
Status published
Products (19)
apache/syncope 1.0.0
apache/syncope 1.0.3
apache/syncope 1.0.4
apache/syncope 1.0.5
apache/syncope 1.0.6
apache/syncope 1.0.7
apache/syncope 1.0.8
apache/syncope 1.0.9
apache/syncope 1.1.0
apache/syncope 1.1.1
... and 9 more
Published Mar 20, 2018
Tracked Since Feb 18, 2026