Sploitus

CVE-2018-1322

4 known exploits for CVE-2018-1322

An administrator with user search entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x which may be also affected, can recover sensitive security values using the fiql and orderby parameters.

Affected products
Apache Syncope
Apache Syncope
< 1.2.11, 2.0.8, 1.0.0, 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.0.7, 1.0.8, 1.0.9, 1.1.0, 1.1.1, 1.1.2, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8
Fix
Available
CVSS 3.0
4.9 MEDIUM
EPSS
20.1% (97th percentile)
Weakness
CWE-200
NVD status
Modified
Published
2018-03-20
CVE-2018-1322 at NVD
Authoritative description, scoring and affected products

4 known exploits for CVE-2018-1322

Proof-of-concept code and exploit modules indexed by Sploitus