Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40902
HistoryJun 15, 2023 - 4:48 a.m.

Improper Access Control

2023-06-1504:48:41
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
4
vulnerability
isolation
library
remote
authenticated users
virtual instances
oauth2
administration page
software

4.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

0.001 Low

EPSS

Percentile

30.0%

com.liferay.object.web is vulnerable to Improper Access Control. The vulnerability exists because the object module in the library does isolate objects in different virtual instances, which allows remote authenticated users in one virtual instance to view objects in a separate virtual instance via the OAuth2 scope administration page.

4.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

0.001 Low

EPSS

Percentile

30.0%