4.3

CVE-2023-33947

The Object module in Liferay Portal 7.4.3.4 through 7.4.3.60, and Liferay DXP 7.4 before update 61 does not segment object definition by virtual instance in search which allows remote authenticated users in one virtual instance to view object definition from a second virtual instance by searching for the object definition.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LiferayDigital Experience Platform Version7.4 Updateupdate1
LiferayDigital Experience Platform Version7.4 Updateupdate10
LiferayDigital Experience Platform Version7.4 Updateupdate11
LiferayDigital Experience Platform Version7.4 Updateupdate12
LiferayDigital Experience Platform Version7.4 Updateupdate13
LiferayDigital Experience Platform Version7.4 Updateupdate14
LiferayDigital Experience Platform Version7.4 Updateupdate15
LiferayDigital Experience Platform Version7.4 Updateupdate16
LiferayDigital Experience Platform Version7.4 Updateupdate17
LiferayDigital Experience Platform Version7.4 Updateupdate18
LiferayDigital Experience Platform Version7.4 Updateupdate19
LiferayDigital Experience Platform Version7.4 Updateupdate2
LiferayDigital Experience Platform Version7.4 Updateupdate20
LiferayDigital Experience Platform Version7.4 Updateupdate21
LiferayDigital Experience Platform Version7.4 Updateupdate22
LiferayDigital Experience Platform Version7.4 Updateupdate23
LiferayDigital Experience Platform Version7.4 Updateupdate24
LiferayDigital Experience Platform Version7.4 Updateupdate25
LiferayDigital Experience Platform Version7.4 Updateupdate26
LiferayDigital Experience Platform Version7.4 Updateupdate27
LiferayDigital Experience Platform Version7.4 Updateupdate28
LiferayDigital Experience Platform Version7.4 Updateupdate29
LiferayDigital Experience Platform Version7.4 Updateupdate3
LiferayDigital Experience Platform Version7.4 Updateupdate30
LiferayDigital Experience Platform Version7.4 Updateupdate31
LiferayDigital Experience Platform Version7.4 Updateupdate32
LiferayDigital Experience Platform Version7.4 Updateupdate33
LiferayDigital Experience Platform Version7.4 Updateupdate34
LiferayDigital Experience Platform Version7.4 Updateupdate35
LiferayDigital Experience Platform Version7.4 Updateupdate36
LiferayDigital Experience Platform Version7.4 Updateupdate37
LiferayDigital Experience Platform Version7.4 Updateupdate38
LiferayDigital Experience Platform Version7.4 Updateupdate39
LiferayDigital Experience Platform Version7.4 Updateupdate4
LiferayDigital Experience Platform Version7.4 Updateupdate40
LiferayDigital Experience Platform Version7.4 Updateupdate41
LiferayDigital Experience Platform Version7.4 Updateupdate42
LiferayDigital Experience Platform Version7.4 Updateupdate43
LiferayDigital Experience Platform Version7.4 Updateupdate44
LiferayDigital Experience Platform Version7.4 Updateupdate45
LiferayDigital Experience Platform Version7.4 Updateupdate46
LiferayDigital Experience Platform Version7.4 Updateupdate47
LiferayDigital Experience Platform Version7.4 Updateupdate48
LiferayDigital Experience Platform Version7.4 Updateupdate49
LiferayDigital Experience Platform Version7.4 Updateupdate5
LiferayDigital Experience Platform Version7.4 Updateupdate50
LiferayDigital Experience Platform Version7.4 Updateupdate51
LiferayDigital Experience Platform Version7.4 Updateupdate52
LiferayDigital Experience Platform Version7.4 Updateupdate53
LiferayDigital Experience Platform Version7.4 Updateupdate54
LiferayDigital Experience Platform Version7.4 Updateupdate55
LiferayDigital Experience Platform Version7.4 Updateupdate56
LiferayDigital Experience Platform Version7.4 Updateupdate57
LiferayDigital Experience Platform Version7.4 Updateupdate58
LiferayDigital Experience Platform Version7.4 Updateupdate59
LiferayDigital Experience Platform Version7.4 Updateupdate6
LiferayDigital Experience Platform Version7.4 Updateupdate60
LiferayDigital Experience Platform Version7.4 Updateupdate7
LiferayDigital Experience Platform Version7.4 Updateupdate8
LiferayDigital Experience Platform Version7.4 Updateupdate9
LiferayLiferay Portal Version >= 7.4.3.4 <= 7.4.3.60
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.15% 0.355
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
security@liferay.com 2.7 1.2 1.4
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.