CVE-2018-1322 EXPLOIT
4.9
MEDIUM · CVSS 3.0 · EPSS 19.9% (pctl 97)
Patch early
A public exploit exists.
Description
An administrator with user search entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x which may be also affected, can recover sensitive security values using the fiql and orderby parameters.
Scoring
| CVSS | 4.9 (MEDIUM, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
| EPSS | 19.92% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-200 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2018-03-20 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| apache | syncope |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Apache Syncope 2.0.7 - Remote Code Execution | 2018-09-13 |
References
- http://syncope.apache.org/security.html#CVE-2018-1322:_Information_disclosure_via_FIQL_and_ORDER_BY_sorting
- http://www.securityfocus.com/bid/103507
- https://www.exploit-db.com/exploits/45400/
- http://syncope.apache.org/security.html#CVE-2018-1322:_Information_disclosure_via_FIQL_and_ORDER_BY_sorting
- http://www.securityfocus.com/bid/103507
- https://www.exploit-db.com/exploits/45400/
→ the Explorer · watch your stack · NVD