CVE-2018-1322 | Apache Syncope up to 1.2.10/2.0.7 Search fiql/orderby information disclosure (EDB-45400 / BID-103507)
A vulnerability, which was classified as problematic, was found in Apache Syncope up to 1.2.10/2.0.7. This impacts an unknown function of the component Search. The manipulation of the argument fiql/orderby as part of Parameter results in information disclosure.
This vulnerability is identified as CVE-2018-1322. The attack can be executed remotely. Additionally, an exploit exists.
You should upgrade the affected component.