6.5

CVE-2020-13444

Liferay Portal 7.x before 7.3.2, and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 5 does not sanitize the information returned by the DDMDataProvider API, which allows remote authenticated users to obtain the password to REST Data Providers.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LiferayLiferay Portal Version7.1 Updatega1 SwEditioncommunity
LiferayLiferay Portal Version7.1 Updatega2 SwEditioncommunity
LiferayLiferay Portal Version7.1 Updatega3 SwEditioncommunity
LiferayLiferay Portal Version7.1.1 Updatega2 SwEditioncommunity
LiferayLiferay Portal Version7.2 Updatega1 SwEditioncommunity
LiferayLiferay Portal Version7.3 Updatega1 SwEditioncommunity
LiferayLiferay Portal Version7.3 Updatega2 SwEditioncommunity
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.25% 0.48
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N