CVE-2020-15841Insufficiently Protected Credentials in Portal

Severity
8.8HIGHNVD
CNA8.3
EPSS
0.3%
top 43.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 20
Latest updateMay 24

Description

Liferay Portal before 7.3.0, and Liferay DXP 7.0 before fix pack 89, 7.1 before fix pack 17, and 7.2 before fix pack 4, does not safely test a connection to a LDAP server, which allows remote attackers to obtain the LDAP server's password via the Test LDAP Connection feature.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

Patches

🔴Vulnerability Details

3
GHSA
Liferay Portal and Liferay DXP Potentially Reveal LDAP Server Password via Unsafe Connection2022-05-24
OSV
Liferay Portal and Liferay DXP Potentially Reveal LDAP Server Password via Unsafe Connection2022-05-24
CVEList
CVE-2020-15841: Liferay Portal before 72020-07-20
CVE-2020-15841 — Insufficiently Protected Credentials | cvebase