Lucene search

K
cveMitreCVE-2021-38266
HistoryMar 02, 2022 - 11:15 p.m.

CVE-2021-38266

2022-03-0223:15:08
mitre
web.nvd.nist.gov
49
2
cve-2021-38266
liferay portal
ldap
security vulnerability
user authentication
remote attackers

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.003

Percentile

72.0%

The Portal Security module in Liferay Portal 7.2.1 and earlier, and Liferay DXP 7.0 before fix pack 90, 7.1 before fix pack 17 and 7.2 before fix pack 5 does not correctly import users from LDAP, which allows remote attackers to prevent a legitimate user from authenticating by attempting to sign in as a user that exist in LDAP.

Affected configurations

Nvd
Node
liferayliferay_portalRange7.2.1community
Node
liferaydigital_experience_platformMatch7.0-
OR
liferaydigital_experience_platformMatch7.0fix_pack_1
OR
liferaydigital_experience_platformMatch7.0fix_pack_10
OR
liferaydigital_experience_platformMatch7.0fix_pack_11
OR
liferaydigital_experience_platformMatch7.0fix_pack_12
OR
liferaydigital_experience_platformMatch7.0fix_pack_13
OR
liferaydigital_experience_platformMatch7.0fix_pack_14
OR
liferaydigital_experience_platformMatch7.0fix_pack_15
OR
liferaydigital_experience_platformMatch7.0fix_pack_16
OR
liferaydigital_experience_platformMatch7.0fix_pack_17
OR
liferaydigital_experience_platformMatch7.0fix_pack_18
OR
liferaydigital_experience_platformMatch7.0fix_pack_19
OR
liferaydigital_experience_platformMatch7.0fix_pack_2
OR
liferaydigital_experience_platformMatch7.0fix_pack_20
OR
liferaydigital_experience_platformMatch7.0fix_pack_21
OR
liferaydigital_experience_platformMatch7.0fix_pack_22
OR
liferaydigital_experience_platformMatch7.0fix_pack_23
OR
liferaydigital_experience_platformMatch7.0fix_pack_24
OR
liferaydigital_experience_platformMatch7.0fix_pack_25
OR
liferaydigital_experience_platformMatch7.0fix_pack_26
OR
liferaydigital_experience_platformMatch7.0fix_pack_27
OR
liferaydigital_experience_platformMatch7.0fix_pack_28
OR
liferaydigital_experience_platformMatch7.0fix_pack_29
OR
liferaydigital_experience_platformMatch7.0fix_pack_3
OR
liferaydigital_experience_platformMatch7.0fix_pack_30
OR
liferaydigital_experience_platformMatch7.0fix_pack_31
OR
liferaydigital_experience_platformMatch7.0fix_pack_32
OR
liferaydigital_experience_platformMatch7.0fix_pack_33
OR
liferaydigital_experience_platformMatch7.0fix_pack_34
OR
liferaydigital_experience_platformMatch7.0fix_pack_35
OR
liferaydigital_experience_platformMatch7.0fix_pack_36
OR
liferaydigital_experience_platformMatch7.0fix_pack_37
OR
liferaydigital_experience_platformMatch7.0fix_pack_38
OR
liferaydigital_experience_platformMatch7.0fix_pack_39
OR
liferaydigital_experience_platformMatch7.0fix_pack_4
OR
liferaydigital_experience_platformMatch7.0fix_pack_40
OR
liferaydigital_experience_platformMatch7.0fix_pack_41
OR
liferaydigital_experience_platformMatch7.0fix_pack_42
OR
liferaydigital_experience_platformMatch7.0fix_pack_43
OR
liferaydigital_experience_platformMatch7.0fix_pack_44
OR
liferaydigital_experience_platformMatch7.0fix_pack_45
OR
liferaydigital_experience_platformMatch7.0fix_pack_46
OR
liferaydigital_experience_platformMatch7.0fix_pack_47
OR
liferaydigital_experience_platformMatch7.0fix_pack_48
OR
liferaydigital_experience_platformMatch7.0fix_pack_49
OR
liferaydigital_experience_platformMatch7.0fix_pack_5
OR
liferaydigital_experience_platformMatch7.0fix_pack_50
OR
liferaydigital_experience_platformMatch7.0fix_pack_51
OR
liferaydigital_experience_platformMatch7.0fix_pack_52
OR
liferaydigital_experience_platformMatch7.0fix_pack_53
OR
liferaydigital_experience_platformMatch7.0fix_pack_54
OR
liferaydigital_experience_platformMatch7.0fix_pack_55
OR
liferaydigital_experience_platformMatch7.0fix_pack_56
OR
liferaydigital_experience_platformMatch7.0fix_pack_57
OR
liferaydigital_experience_platformMatch7.0fix_pack_58
OR
liferaydigital_experience_platformMatch7.0fix_pack_59
OR
liferaydigital_experience_platformMatch7.0fix_pack_6
OR
liferaydigital_experience_platformMatch7.0fix_pack_60
OR
liferaydigital_experience_platformMatch7.0fix_pack_61
OR
liferaydigital_experience_platformMatch7.0fix_pack_62
OR
liferaydigital_experience_platformMatch7.0fix_pack_63
OR
liferaydigital_experience_platformMatch7.0fix_pack_64
OR
liferaydigital_experience_platformMatch7.0fix_pack_65
OR
liferaydigital_experience_platformMatch7.0fix_pack_66
OR
liferaydigital_experience_platformMatch7.0fix_pack_67
OR
liferaydigital_experience_platformMatch7.0fix_pack_68
OR
liferaydigital_experience_platformMatch7.0fix_pack_69
OR
liferaydigital_experience_platformMatch7.0fix_pack_7
OR
liferaydigital_experience_platformMatch7.0fix_pack_70
OR
liferaydigital_experience_platformMatch7.0fix_pack_71
OR
liferaydigital_experience_platformMatch7.0fix_pack_72
OR
liferaydigital_experience_platformMatch7.0fix_pack_73
OR
liferaydigital_experience_platformMatch7.0fix_pack_74
OR
liferaydigital_experience_platformMatch7.0fix_pack_75
OR
liferaydigital_experience_platformMatch7.0fix_pack_76
OR
liferaydigital_experience_platformMatch7.0fix_pack_77
OR
liferaydigital_experience_platformMatch7.0fix_pack_78
OR
liferaydigital_experience_platformMatch7.0fix_pack_79
OR
liferaydigital_experience_platformMatch7.0fix_pack_8
OR
liferaydigital_experience_platformMatch7.0fix_pack_80
OR
liferaydigital_experience_platformMatch7.0fix_pack_81
OR
liferaydigital_experience_platformMatch7.0fix_pack_82
OR
liferaydigital_experience_platformMatch7.0fix_pack_83
OR
liferaydigital_experience_platformMatch7.0fix_pack_84
OR
liferaydigital_experience_platformMatch7.0fix_pack_85
OR
liferaydigital_experience_platformMatch7.0fix_pack_86
OR
liferaydigital_experience_platformMatch7.0fix_pack_87
OR
liferaydigital_experience_platformMatch7.0fix_pack_88
OR
liferaydigital_experience_platformMatch7.0fix_pack_89
OR
liferaydigital_experience_platformMatch7.0fix_pack_9
OR
liferaydigital_experience_platformMatch7.1-
OR
liferaydigital_experience_platformMatch7.1fix_pack_1
OR
liferaydigital_experience_platformMatch7.1fix_pack_10
OR
liferaydigital_experience_platformMatch7.1fix_pack_11
OR
liferaydigital_experience_platformMatch7.1fix_pack_12
OR
liferaydigital_experience_platformMatch7.1fix_pack_13
OR
liferaydigital_experience_platformMatch7.1fix_pack_14
OR
liferaydigital_experience_platformMatch7.1fix_pack_15
OR
liferaydigital_experience_platformMatch7.1fix_pack_16
OR
liferaydigital_experience_platformMatch7.1fix_pack_2
OR
liferaydigital_experience_platformMatch7.1fix_pack_3
OR
liferaydigital_experience_platformMatch7.1fix_pack_4
OR
liferaydigital_experience_platformMatch7.1fix_pack_5
OR
liferaydigital_experience_platformMatch7.1fix_pack_6
OR
liferaydigital_experience_platformMatch7.1fix_pack_7
OR
liferaydigital_experience_platformMatch7.1fix_pack_8
OR
liferaydigital_experience_platformMatch7.1fix_pack_9
OR
liferaydigital_experience_platformMatch7.2-
OR
liferaydigital_experience_platformMatch7.2fix_pack_1
OR
liferaydigital_experience_platformMatch7.2fix_pack_2
OR
liferaydigital_experience_platformMatch7.2fix_pack_3
OR
liferaydigital_experience_platformMatch7.2fix_pack_4
VendorProductVersionCPE
liferayliferay_portal*cpe:2.3:a:liferay:liferay_portal:*:*:*:*:community:*:*:*
liferaydigital_experience_platform7.0cpe:2.3:a:liferay:digital_experience_platform:7.0:-:*:*:*:*:*:*
liferaydigital_experience_platform7.0cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_1:*:*:*:*:*:*
liferaydigital_experience_platform7.0cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_10:*:*:*:*:*:*
liferaydigital_experience_platform7.0cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_11:*:*:*:*:*:*
liferaydigital_experience_platform7.0cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_12:*:*:*:*:*:*
liferaydigital_experience_platform7.0cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_13:*:*:*:*:*:*
liferaydigital_experience_platform7.0cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_14:*:*:*:*:*:*
liferaydigital_experience_platform7.0cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_15:*:*:*:*:*:*
liferaydigital_experience_platform7.0cpe:2.3:a:liferay:digital_experience_platform:7.0:fix_pack_16:*:*:*:*:*:*
Rows per page:
1-10 of 1131

Social References

More

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.003

Percentile

72.0%

Related for CVE-2021-38266