6.5
CVE-2020-13444
- EPSS 0.25%
- Published 10.06.2020 19:15:09
- Last modified 21.11.2024 05:01:16
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
Liferay Portal 7.x before 7.3.2, and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 5 does not sanitize the information returned by the DDMDataProvider API, which allows remote authenticated users to obtain the password to REST Data Providers.
Data is provided by the National Vulnerability Database (NVD)
Liferay ≫ Liferay Portal Version7.1 Updatega1 SwEditioncommunity
Liferay ≫ Liferay Portal Version7.1 Updatega2 SwEditioncommunity
Liferay ≫ Liferay Portal Version7.1 Updatega3 SwEditioncommunity
Liferay ≫ Liferay Portal Version7.1.1 Updatega2 SwEditioncommunity
Liferay ≫ Liferay Portal Version7.2 Updatega1 SwEditioncommunity
Liferay ≫ Liferay Portal Version7.3 Updatega1 SwEditioncommunity
Liferay ≫ Liferay Portal Version7.3 Updatega2 SwEditioncommunity
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.25% | 0.48 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
nvd@nist.gov | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:P/I:N/A:N
|