6.5

CVE-2020-13444

Liferay Portal 7.x before 7.3.2, and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 5 does not sanitize the information returned by the DDMDataProvider API, which allows remote authenticated users to obtain the password to REST Data Providers.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Liferay ≫ Liferay Portal Version 7.1 Update ga1 SwEdition community
Liferay ≫ Liferay Portal Version 7.1 Update ga2 SwEdition community
Liferay ≫ Liferay Portal Version 7.1 Update ga3 SwEdition community
Liferay ≫ Liferay Portal Version 7.1.1 Update ga2 SwEdition community
Liferay ≫ Liferay Portal Version 7.2 Update ga1 SwEdition community
Liferay ≫ Liferay Portal Version 7.3 Update ga1 SwEdition community
Liferay ≫ Liferay Portal Version 7.3 Update ga2 SwEdition community
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.59% 0.725
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
NIST 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://issues.liferay.com/browse/LPE-17009
https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/id/119317396
Patch
Vendor Advisory