6.3
CVE-2022-45320
- EPSS 0.53%
- Veröffentlicht 20.02.2024 05:15:07
- Zuletzt bearbeitet 28.03.2025 21:15:14
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
Liferay Portal before 7.4.3.16 and Liferay DXP before 7.2 fix pack 19, 7.3 before update 6, and 7.4 before update 16 allow remote authenticated users to become the owner of a wiki page by editing the wiki page.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Liferay ≫ Digital Experience Platform Version < 7.2
Liferay ≫ Digital Experience Platform Version7.2 Update-
Liferay ≫ Digital Experience Platform Version7.2 Updatefix_pack_1
Liferay ≫ Digital Experience Platform Version7.2 Updatefix_pack_10
Liferay ≫ Digital Experience Platform Version7.2 Updatefix_pack_11
Liferay ≫ Digital Experience Platform Version7.2 Updatefix_pack_12
Liferay ≫ Digital Experience Platform Version7.2 Updatefix_pack_13
Liferay ≫ Digital Experience Platform Version7.2 Updatefix_pack_14
Liferay ≫ Digital Experience Platform Version7.2 Updatefix_pack_15
Liferay ≫ Digital Experience Platform Version7.2 Updatefix_pack_16
Liferay ≫ Digital Experience Platform Version7.2 Updatefix_pack_17
Liferay ≫ Digital Experience Platform Version7.2 Updatefix_pack_18
Liferay ≫ Digital Experience Platform Version7.2 Updatefix_pack_2
Liferay ≫ Digital Experience Platform Version7.2 Updatefix_pack_3
Liferay ≫ Digital Experience Platform Version7.2 Updatefix_pack_4
Liferay ≫ Digital Experience Platform Version7.2 Updatefix_pack_5
Liferay ≫ Digital Experience Platform Version7.2 Updatefix_pack_6
Liferay ≫ Digital Experience Platform Version7.2 Updatefix_pack_7
Liferay ≫ Digital Experience Platform Version7.2 Updatefix_pack_8
Liferay ≫ Digital Experience Platform Version7.2 Updatefix_pack_9
Liferay ≫ Digital Experience Platform Version7.2 Updateservice_pack_1
Liferay ≫ Digital Experience Platform Version7.2 Updateservice_pack_2
Liferay ≫ Digital Experience Platform Version7.2 Updateservice_pack_3
Liferay ≫ Digital Experience Platform Version7.2 Updateservice_pack_4
Liferay ≫ Digital Experience Platform Version7.2 Updateservice_pack_5
Liferay ≫ Digital Experience Platform Version7.2 Updateservice_pack_6
Liferay ≫ Digital Experience Platform Version7.2 Updateservice_pack_7
Liferay ≫ Digital Experience Platform Version7.2 Updateservice_pack_8
Liferay ≫ Digital Experience Platform Version7.3 Update-
Liferay ≫ Digital Experience Platform Version7.3 Updatefix_pack_1
Liferay ≫ Digital Experience Platform Version7.3 Updatefix_pack_2
Liferay ≫ Digital Experience Platform Version7.3 Updateservice_pack_1
Liferay ≫ Digital Experience Platform Version7.3 Updateservice_pack_3
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate4
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate5
Liferay ≫ Digital Experience Platform Version7.4 Update-
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate1
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate10
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate11
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate12
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate13
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate14
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate15
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate2
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate3
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate4
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate5
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate6
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate7
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate8
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate9
Liferay ≫ Liferay Portal Version < 7.4.3.16
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.53% | 0.66 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 6.3 | 2.8 | 3.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
|
134c704f-9b21-4f2e-91b3-4a467353bcc0 | 6.3 | 2.8 | 3.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.