Information Disclosure in Apache Syncope Affected by Improper Access Control
CVE-2018-1322
4.9MEDIUM
Summary
An information disclosure vulnerability exists in Apache Syncope, where an administrator with user search rights can inadvertently exploit the fiql and orderby parameters to recover sensitive security values. This issue affects various versions of Apache Syncope, including older and unsupported releases, increasing the risk of unauthorized data exposure.
Affected Version(s)
Apache Syncope Releases prior to 1.2.11, Releases prior to 2.0.8
Apache Syncope The unsupported Releases 1.0.x, 1.1.x may be also affected.
References
CVSS V3.1
Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved