7.5

CVE-2021-38266

The Portal Security module in Liferay Portal 7.2.1 and earlier, and Liferay DXP 7.0 before fix pack 90, 7.1 before fix pack 17 and 7.2 before fix pack 5 does not correctly import users from LDAP, which allows remote attackers to prevent a legitimate user from authenticating by attempting to sign in as a user that exist in LDAP.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LiferayLiferay Portal SwEditioncommunity Version <= 7.2.1
LiferayDigital Experience Platform Version7.0 Update-
LiferayDigital Experience Platform Version7.0 Updatefix_pack_1
LiferayDigital Experience Platform Version7.0 Updatefix_pack_10
LiferayDigital Experience Platform Version7.0 Updatefix_pack_11
LiferayDigital Experience Platform Version7.0 Updatefix_pack_12
LiferayDigital Experience Platform Version7.0 Updatefix_pack_13
LiferayDigital Experience Platform Version7.0 Updatefix_pack_14
LiferayDigital Experience Platform Version7.0 Updatefix_pack_15
LiferayDigital Experience Platform Version7.0 Updatefix_pack_16
LiferayDigital Experience Platform Version7.0 Updatefix_pack_17
LiferayDigital Experience Platform Version7.0 Updatefix_pack_18
LiferayDigital Experience Platform Version7.0 Updatefix_pack_19
LiferayDigital Experience Platform Version7.0 Updatefix_pack_2
LiferayDigital Experience Platform Version7.0 Updatefix_pack_20
LiferayDigital Experience Platform Version7.0 Updatefix_pack_21
LiferayDigital Experience Platform Version7.0 Updatefix_pack_22
LiferayDigital Experience Platform Version7.0 Updatefix_pack_23
LiferayDigital Experience Platform Version7.0 Updatefix_pack_24
LiferayDigital Experience Platform Version7.0 Updatefix_pack_25
LiferayDigital Experience Platform Version7.0 Updatefix_pack_26
LiferayDigital Experience Platform Version7.0 Updatefix_pack_27
LiferayDigital Experience Platform Version7.0 Updatefix_pack_28
LiferayDigital Experience Platform Version7.0 Updatefix_pack_29
LiferayDigital Experience Platform Version7.0 Updatefix_pack_3
LiferayDigital Experience Platform Version7.0 Updatefix_pack_30
LiferayDigital Experience Platform Version7.0 Updatefix_pack_31
LiferayDigital Experience Platform Version7.0 Updatefix_pack_32
LiferayDigital Experience Platform Version7.0 Updatefix_pack_33
LiferayDigital Experience Platform Version7.0 Updatefix_pack_34
LiferayDigital Experience Platform Version7.0 Updatefix_pack_35
LiferayDigital Experience Platform Version7.0 Updatefix_pack_36
LiferayDigital Experience Platform Version7.0 Updatefix_pack_37
LiferayDigital Experience Platform Version7.0 Updatefix_pack_38
LiferayDigital Experience Platform Version7.0 Updatefix_pack_39
LiferayDigital Experience Platform Version7.0 Updatefix_pack_4
LiferayDigital Experience Platform Version7.0 Updatefix_pack_40
LiferayDigital Experience Platform Version7.0 Updatefix_pack_41
LiferayDigital Experience Platform Version7.0 Updatefix_pack_42
LiferayDigital Experience Platform Version7.0 Updatefix_pack_43
LiferayDigital Experience Platform Version7.0 Updatefix_pack_44
LiferayDigital Experience Platform Version7.0 Updatefix_pack_45
LiferayDigital Experience Platform Version7.0 Updatefix_pack_46
LiferayDigital Experience Platform Version7.0 Updatefix_pack_47
LiferayDigital Experience Platform Version7.0 Updatefix_pack_48
LiferayDigital Experience Platform Version7.0 Updatefix_pack_49
LiferayDigital Experience Platform Version7.0 Updatefix_pack_5
LiferayDigital Experience Platform Version7.0 Updatefix_pack_50
LiferayDigital Experience Platform Version7.0 Updatefix_pack_51
LiferayDigital Experience Platform Version7.0 Updatefix_pack_52
LiferayDigital Experience Platform Version7.0 Updatefix_pack_53
LiferayDigital Experience Platform Version7.0 Updatefix_pack_54
LiferayDigital Experience Platform Version7.0 Updatefix_pack_55
LiferayDigital Experience Platform Version7.0 Updatefix_pack_56
LiferayDigital Experience Platform Version7.0 Updatefix_pack_57
LiferayDigital Experience Platform Version7.0 Updatefix_pack_58
LiferayDigital Experience Platform Version7.0 Updatefix_pack_59
LiferayDigital Experience Platform Version7.0 Updatefix_pack_6
LiferayDigital Experience Platform Version7.0 Updatefix_pack_60
LiferayDigital Experience Platform Version7.0 Updatefix_pack_61
LiferayDigital Experience Platform Version7.0 Updatefix_pack_62
LiferayDigital Experience Platform Version7.0 Updatefix_pack_63
LiferayDigital Experience Platform Version7.0 Updatefix_pack_64
LiferayDigital Experience Platform Version7.0 Updatefix_pack_65
LiferayDigital Experience Platform Version7.0 Updatefix_pack_66
LiferayDigital Experience Platform Version7.0 Updatefix_pack_67
LiferayDigital Experience Platform Version7.0 Updatefix_pack_68
LiferayDigital Experience Platform Version7.0 Updatefix_pack_69
LiferayDigital Experience Platform Version7.0 Updatefix_pack_7
LiferayDigital Experience Platform Version7.0 Updatefix_pack_70
LiferayDigital Experience Platform Version7.0 Updatefix_pack_71
LiferayDigital Experience Platform Version7.0 Updatefix_pack_72
LiferayDigital Experience Platform Version7.0 Updatefix_pack_73
LiferayDigital Experience Platform Version7.0 Updatefix_pack_74
LiferayDigital Experience Platform Version7.0 Updatefix_pack_75
LiferayDigital Experience Platform Version7.0 Updatefix_pack_76
LiferayDigital Experience Platform Version7.0 Updatefix_pack_77
LiferayDigital Experience Platform Version7.0 Updatefix_pack_78
LiferayDigital Experience Platform Version7.0 Updatefix_pack_79
LiferayDigital Experience Platform Version7.0 Updatefix_pack_8
LiferayDigital Experience Platform Version7.0 Updatefix_pack_80
LiferayDigital Experience Platform Version7.0 Updatefix_pack_81
LiferayDigital Experience Platform Version7.0 Updatefix_pack_82
LiferayDigital Experience Platform Version7.0 Updatefix_pack_83
LiferayDigital Experience Platform Version7.0 Updatefix_pack_84
LiferayDigital Experience Platform Version7.0 Updatefix_pack_85
LiferayDigital Experience Platform Version7.0 Updatefix_pack_86
LiferayDigital Experience Platform Version7.0 Updatefix_pack_87
LiferayDigital Experience Platform Version7.0 Updatefix_pack_88
LiferayDigital Experience Platform Version7.0 Updatefix_pack_89
LiferayDigital Experience Platform Version7.0 Updatefix_pack_9
LiferayDigital Experience Platform Version7.1 Update-
LiferayDigital Experience Platform Version7.1 Updatefix_pack_1
LiferayDigital Experience Platform Version7.1 Updatefix_pack_10
LiferayDigital Experience Platform Version7.1 Updatefix_pack_11
LiferayDigital Experience Platform Version7.1 Updatefix_pack_12
LiferayDigital Experience Platform Version7.1 Updatefix_pack_13
LiferayDigital Experience Platform Version7.1 Updatefix_pack_14
LiferayDigital Experience Platform Version7.1 Updatefix_pack_15
LiferayDigital Experience Platform Version7.1 Updatefix_pack_16
LiferayDigital Experience Platform Version7.1 Updatefix_pack_2
LiferayDigital Experience Platform Version7.1 Updatefix_pack_3
LiferayDigital Experience Platform Version7.1 Updatefix_pack_4
LiferayDigital Experience Platform Version7.1 Updatefix_pack_5
LiferayDigital Experience Platform Version7.1 Updatefix_pack_6
LiferayDigital Experience Platform Version7.1 Updatefix_pack_7
LiferayDigital Experience Platform Version7.1 Updatefix_pack_8
LiferayDigital Experience Platform Version7.1 Updatefix_pack_9
LiferayDigital Experience Platform Version7.2 Update-
LiferayDigital Experience Platform Version7.2 Updatefix_pack_1
LiferayDigital Experience Platform Version7.2 Updatefix_pack_2
LiferayDigital Experience Platform Version7.2 Updatefix_pack_3
LiferayDigital Experience Platform Version7.2 Updatefix_pack_4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.85% 0.825
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P