#VU15645 Information disclosure in Apache Syncope - CVE-2018-1322
Published: October 31, 2018 / Updated: June 17, 2021
Apache Syncope
Apache Foundation
Description
The vulnerability allows a remote authenticated attacker to gain access to potentially sensitive information.
The vulnerability exists due to unspecified error related to processing of the fiql and orderby parameters. A remote authenticated administrator with user search entitlements can gain unauthorized access to sensitive information on the system.