5.3

CVE-2024-26268

User enumeration vulnerability in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 before update 27, 7.3 before update 8, 7.2 before fix pack 20, and older unsupported versions allows remote attackers to determine if an account exist in the application by comparing the request's response time.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LiferayLiferay Portal Version <= 7.3.7
LiferayLiferay Portal Version >= 7.4.0 < 7.4.3.27
LiferayDigital Experience Platform Version7.2 Update-
LiferayDigital Experience Platform Version7.2 Updatefix_pack_1
LiferayDigital Experience Platform Version7.2 Updatefix_pack_10
LiferayDigital Experience Platform Version7.2 Updatefix_pack_11
LiferayDigital Experience Platform Version7.2 Updatefix_pack_12
LiferayDigital Experience Platform Version7.2 Updatefix_pack_13
LiferayDigital Experience Platform Version7.2 Updatefix_pack_14
LiferayDigital Experience Platform Version7.2 Updatefix_pack_15
LiferayDigital Experience Platform Version7.2 Updatefix_pack_16
LiferayDigital Experience Platform Version7.2 Updatefix_pack_17
LiferayDigital Experience Platform Version7.2 Updatefix_pack_18
LiferayDigital Experience Platform Version7.2 Updatefix_pack_19
LiferayDigital Experience Platform Version7.2 Updatefix_pack_2
LiferayDigital Experience Platform Version7.2 Updatefix_pack_3
LiferayDigital Experience Platform Version7.2 Updatefix_pack_4
LiferayDigital Experience Platform Version7.2 Updatefix_pack_5
LiferayDigital Experience Platform Version7.2 Updatefix_pack_6
LiferayDigital Experience Platform Version7.2 Updatefix_pack_7
LiferayDigital Experience Platform Version7.2 Updatefix_pack_8
LiferayDigital Experience Platform Version7.2 Updatefix_pack_9
LiferayDigital Experience Platform Version7.2 Updateservice_pack_1
LiferayDigital Experience Platform Version7.2 Updateservice_pack_2
LiferayDigital Experience Platform Version7.2 Updateservice_pack_3
LiferayDigital Experience Platform Version7.2 Updateservice_pack_4
LiferayDigital Experience Platform Version7.2 Updateservice_pack_5
LiferayDigital Experience Platform Version7.2 Updateservice_pack_6
LiferayDigital Experience Platform Version7.2 Updateservice_pack_7
LiferayDigital Experience Platform Version7.3 Update-
LiferayDigital Experience Platform Version7.3 Updatefix_pack_1
LiferayDigital Experience Platform Version7.3 Updatefix_pack_2
LiferayDigital Experience Platform Version7.3 Updateservice_pack_1
LiferayDigital Experience Platform Version7.3 Updateservice_pack_3
LiferayDigital Experience Platform Version7.3 Updateupdate4
LiferayDigital Experience Platform Version7.3 Updateupdate5
LiferayDigital Experience Platform Version7.3 Updateupdate6
LiferayDigital Experience Platform Version7.3 Updateupdate7
LiferayDigital Experience Platform Version7.4 Update-
LiferayDigital Experience Platform Version7.4 Updateupdate1
LiferayDigital Experience Platform Version7.4 Updateupdate10
LiferayDigital Experience Platform Version7.4 Updateupdate11
LiferayDigital Experience Platform Version7.4 Updateupdate12
LiferayDigital Experience Platform Version7.4 Updateupdate13
LiferayDigital Experience Platform Version7.4 Updateupdate14
LiferayDigital Experience Platform Version7.4 Updateupdate15
LiferayDigital Experience Platform Version7.4 Updateupdate16
LiferayDigital Experience Platform Version7.4 Updateupdate17
LiferayDigital Experience Platform Version7.4 Updateupdate18
LiferayDigital Experience Platform Version7.4 Updateupdate19
LiferayDigital Experience Platform Version7.4 Updateupdate2
LiferayDigital Experience Platform Version7.4 Updateupdate20
LiferayDigital Experience Platform Version7.4 Updateupdate21
LiferayDigital Experience Platform Version7.4 Updateupdate22
LiferayDigital Experience Platform Version7.4 Updateupdate23
LiferayDigital Experience Platform Version7.4 Updateupdate24
LiferayDigital Experience Platform Version7.4 Updateupdate25
LiferayDigital Experience Platform Version7.4 Updateupdate26
LiferayDigital Experience Platform Version7.4 Updateupdate3
LiferayDigital Experience Platform Version7.4 Updateupdate4
LiferayDigital Experience Platform Version7.4 Updateupdate5
LiferayDigital Experience Platform Version7.4 Updateupdate6
LiferayDigital Experience Platform Version7.4 Updateupdate7
LiferayDigital Experience Platform Version7.4 Updateupdate8
LiferayDigital Experience Platform Version7.4 Updateupdate9
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.3% 0.531
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
security@liferay.com 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-203 Observable Discrepancy

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.