ZeroHour

CVE-2018-1322

CVSS 3.0
4.9 medium
EPSS
20%p97
Published
()
Modified
Description

An administrator with user search entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x which may be also affected, can recover sensitive security values using the fiql and orderby parameters.

Vendors
apache
Products
syncope
Weakness
CWE-200
Vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.