CVE-2020-15841

Liferay Portal before 7.3.0, and Liferay DXP 7.0 before fix pack 89, 7.1 before fix pack 17, and 7.2 before fix pack 4, does not safely test a connection to a LDAP server, which allows remote attackers to obtain the LDAP server's password via the Test LDAP Connection feature.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.3 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
mitreCNA
8.3 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AC:H/AV:N/A:H/C:H/I:H/PR:N/S:C/UI:R
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 55%
VendorProductVersion
liferaydigital_experience_platform
7.0
liferaydigital_experience_platform
7.0:fix_pack_13
liferaydigital_experience_platform
7.0:fix_pack_14
liferaydigital_experience_platform
7.0:fix_pack_24
liferaydigital_experience_platform
7.0:fix_pack_25
liferaydigital_experience_platform
7.0:fix_pack_26
liferaydigital_experience_platform
7.0:fix_pack_27
liferaydigital_experience_platform
7.0:fix_pack_28
liferaydigital_experience_platform
7.0:fix_pack_3
liferaydigital_experience_platform
7.0:fix_pack_30
liferaydigital_experience_platform
7.0:fix_pack_33
liferaydigital_experience_platform
7.0:fix_pack_35
liferaydigital_experience_platform
7.0:fix_pack_36
liferaydigital_experience_platform
7.0:fix_pack_39
liferaydigital_experience_platform
7.0:fix_pack_40
liferaydigital_experience_platform
7.0:fix_pack_41
liferaydigital_experience_platform
7.0:fix_pack_42
liferaydigital_experience_platform
7.0:fix_pack_43
liferaydigital_experience_platform
7.0:fix_pack_44
liferaydigital_experience_platform
7.0:fix_pack_45
liferaydigital_experience_platform
7.0:fix_pack_46
liferaydigital_experience_platform
7.0:fix_pack_47
liferaydigital_experience_platform
7.0:fix_pack_48
liferaydigital_experience_platform
7.0:fix_pack_49
liferaydigital_experience_platform
7.0:fix_pack_50
liferaydigital_experience_platform
7.0:fix_pack_51
liferaydigital_experience_platform
7.0:fix_pack_52
liferaydigital_experience_platform
7.0:fix_pack_53
liferaydigital_experience_platform
7.0:fix_pack_54
liferaydigital_experience_platform
7.0:fix_pack_56
liferaydigital_experience_platform
7.0:fix_pack_57
liferaydigital_experience_platform
7.0:fix_pack_58
liferaydigital_experience_platform
7.0:fix_pack_59
liferaydigital_experience_platform
7.0:fix_pack_60
liferaydigital_experience_platform
7.0:fix_pack_61
liferaydigital_experience_platform
7.0:fix_pack_64
liferaydigital_experience_platform
7.0:fix_pack_65
liferaydigital_experience_platform
7.0:fix_pack_66
liferaydigital_experience_platform
7.0:fix_pack_67
liferaydigital_experience_platform
7.0:fix_pack_68
liferaydigital_experience_platform
7.0:fix_pack_69
liferaydigital_experience_platform
7.0:fix_pack_70
liferaydigital_experience_platform
7.0:fix_pack_71
liferaydigital_experience_platform
7.0:fix_pack_72
liferaydigital_experience_platform
7.0:fix_pack_73
liferaydigital_experience_platform
7.0:fix_pack_75
liferaydigital_experience_platform
7.0:fix_pack_76
liferaydigital_experience_platform
7.0:fix_pack_78
liferaydigital_experience_platform
7.0:fix_pack_79
liferaydigital_experience_platform
7.0:fix_pack_80
liferaydigital_experience_platform
7.0:fix_pack_81
liferaydigital_experience_platform
7.1
liferaydigital_experience_platform
7.1:fix_pack_1
liferaydigital_experience_platform
7.1:fix_pack_10
liferaydigital_experience_platform
7.1:fix_pack_11
liferaydigital_experience_platform
7.1:fix_pack_12
liferaydigital_experience_platform
7.1:fix_pack_13
liferaydigital_experience_platform
7.1:fix_pack_14
liferaydigital_experience_platform
7.1:fix_pack_15
liferaydigital_experience_platform
7.1:fix_pack_16
liferaydigital_experience_platform
7.1:fix_pack_2
liferaydigital_experience_platform
7.1:fix_pack_3
liferaydigital_experience_platform
7.1:fix_pack_4
liferaydigital_experience_platform
7.1:fix_pack_5
liferaydigital_experience_platform
7.1:fix_pack_6
liferaydigital_experience_platform
7.1:fix_pack_7
liferaydigital_experience_platform
7.1:fix_pack_8
liferaydigital_experience_platform
7.1:fix_pack_9
liferaydigital_experience_platform
7.2
liferaydigital_experience_platform
7.2:fix_pack_1
liferaydigital_experience_platform
7.2:fix_pack_2
liferaydigital_experience_platform
7.2:fix_pack_3
liferayliferay_portal
𝑥
< 7.3.0
𝑥
= Vulnerable software versions