Information Disclosure in Apache Syncope Affected by Improper Access Control
CVE-2018-1322

4.9MEDIUM

Key Information:

Vendor
Apache
Vendor
CVE Published:
20 March 2018

Summary

An information disclosure vulnerability exists in Apache Syncope, where an administrator with user search rights can inadvertently exploit the fiql and orderby parameters to recover sensitive security values. This issue affects various versions of Apache Syncope, including older and unsupported releases, increasing the risk of unauthorized data exposure.

Affected Version(s)

Apache Syncope Releases prior to 1.2.11, Releases prior to 2.0.8

Apache Syncope The unsupported Releases 1.0.x, 1.1.x may be also affected.

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.