4
CVSSv2

CVE-2018-1322

Published: 20/03/2018 Updated: 08/03/2019
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.9 | Impact Score: 3.6 | Exploitability Score: 1.2
VMScore: 405
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

An administrator with user search entitlements in Apache Syncope 1.2.x prior to 1.2.11, 2.0.x prior to 2.0.8, and unsupported releases 1.0.x and 1.1.x which may be also affected, can recover sensitive security values using the fiql and orderby parameters.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache syncope

apache syncope 1.1.4

apache syncope 1.1.5

apache syncope 1.1.6

apache syncope 1.1.7

apache syncope 1.0.5

apache syncope 1.0.7

apache syncope 1.0.6

apache syncope 1.0.8

apache syncope 1.0.0

apache syncope 1.0.4

apache syncope 1.0.9

apache syncope 1.1.1

apache syncope 1.1.3

apache syncope 1.1.8

apache syncope 1.0.3

apache syncope 1.1.0

apache syncope 1.1.2

Exploits

# Exploit Title: Apache Syncope 207 - Remote Code Execution # Date: 2018-09-12 # Exploit Author: Che-Chun Kuo # Vendor Homepage: syncopeapacheorg/ # Software Link: archiveapacheorg/dist/syncope/ # Version: 207 # Tested on: Windows # Advisory: syncopeapacheorg/security # CVE: CVE-2018-1321, CVE-2018-1322 # Vulnerabi ...
Apache Syncope version 27 suffers from a remote code execution vulnerability ...