{"cve":{"cve_id":"CVE-2018-1322","is_kev":false,"kev_date_added":null,"kev_vendor_project":null,"kev_product":null,"kev_vulnerability_name":null,"kev_short_description":null,"kev_required_action":null,"kev_due_date":null,"kev_known_ransomware":null,"kev_notes":null,"kev_cwes":null,"epss_score":0.20502,"epss_percentile":0.97175,"epss_as_of":"2026-06-23","description":"An administrator with user search entitlements in Apache Syncope 1.2.x before 1.2.11, 2.0.x before 2.0.8, and unsupported releases 1.0.x and 1.1.x which may be also affected, can recover sensitive security values using the fiql and orderby parameters.","published_at":"2018-03-20T17:00:00Z","last_modified_at":null,"cvss_v3_score":null,"cvss_v3_vector":null,"cvss_v3_severity":null,"cvss_v4_score":null,"cvss_v4_vector":null,"cvss_v4_severity":null,"ssvc_decision":null,"ssvc_exploitation":null,"ssvc_automatable":null,"ssvc_technical_impact":null,"cwes":null,"nvd_references":["http://syncope.apache.org/security.html#CVE-2018-1322:_Information_disclosure_via_FIQL_and_ORDER_BY_sorting","http://www.securityfocus.com/bid/103507","https://www.exploit-db.com/exploits/45400/"],"vuln_status":null,"trending_score":null,"is_trending":false,"has_trended":false,"trended_number_one":false,"trending_peak_score":null,"trending_peak_rank":null,"started_trending_at":null,"trended_number_one_at":null,"summary_generated":null,"summary_generated_at":null,"summary_model":null,"created_at":"2026-06-24T00:09:39.878444Z","updated_at":"2026-06-28T23:10:45.282955Z"},"effective_severity":null,"badges":[],"impact_analysis":[],"cvss_v3_decoded":{"version":null,"metrics":[]},"cvss_v4_decoded":{"version":null,"metrics":[]},"affected":[{"vendor_slug":"apache-software-foundation","vendor_name":"Apache Software Foundation","product_slug":"apache-syncope","product_name":"Apache Syncope","version_start":"Releases prior to 1.2.11, Releases prior to 2.0.8","version_start_inclusive":true,"version_end":"Releases prior to 1.2.11, Releases prior to 2.0.8","version_end_inclusive":true,"cpe23_uri":"cve5:apache-software-foundation:apache-syncope:Releases prior to 1.2.11, Releases prior to 2.0.8:Releases prior to 1.2.11, Releases prior to 2.0.8"},{"vendor_slug":"apache-software-foundation","vendor_name":"Apache Software Foundation","product_slug":"apache-syncope","product_name":"Apache Syncope","version_start":"The unsupported Releases 1.0.x, 1.1.x may be also affected.","version_start_inclusive":true,"version_end":"The unsupported Releases 1.0.x, 1.1.x may be also affected.","version_end_inclusive":true,"cpe23_uri":"cve5:apache-software-foundation:apache-syncope:The unsupported Releases 1.0.x, 1.1.x may be also affected.:The unsupported Releases 1.0.x, 1.1.x may be also affected."}],"exploit_refs":[],"news":[],"references":[{"url":"http://syncope.apache.org/security.html#CVE-2018-1322:_Information_disclosure_via_FIQL_and_ORDER_BY_sorting","source_type":"MISC","tags":[]},{"url":"http://www.securityfocus.com/bid/103507","source_type":"MISC","tags":[]},{"url":"https://www.exploit-db.com/exploits/45400/","source_type":"EXPLOIT","tags":["exploit"]}],"timeline":[{"type":"published","at":"2018-03-20T17:00:00Z","label":"CVE published","source":null}]}