← Back

CVE-2020-15841

nvd nist
Published: Jul 20, 2020Modified: Aug 15, 2025

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

Liferay Portal before 7.3.0, and Liferay DXP 7.0 before fix pack 89, 7.1 before fix pack 17, and 7.2 before fix pack 4, does not safely test a connection to a LDAP server, which allows remote attackers to obtain the LDAP server's password via the Test LDAP Connection feature.

Affected (73)

2 products
Digital Experience Platform
Liferay Portal
Configuration A
73 vulnerable
Vulnerable SoftwareAffected Versions
Liferay
Version 7.0
Version 7.0 fix_pack_13
Version 7.0 fix_pack_14
Version 7.0 fix_pack_24
Version 7.0 fix_pack_25
Version 7.0 fix_pack_26
Version 7.0 fix_pack_27
Version 7.0 fix_pack_28
Version 7.0 fix_pack_30
Version 7.0 fix_pack_33
Version 7.0 fix_pack_35
Version 7.0 fix_pack_36
Version 7.0 fix_pack_39
Version 7.0 fix_pack_3
Version 7.0 fix_pack_40
Version 7.0 fix_pack_41
Version 7.0 fix_pack_42
Version 7.0 fix_pack_43
Version 7.0 fix_pack_44
Version 7.0 fix_pack_45
Version 7.0 fix_pack_46
Version 7.0 fix_pack_47
Version 7.0 fix_pack_48
Version 7.0 fix_pack_49
Version 7.0 fix_pack_50
Version 7.0 fix_pack_51
Version 7.0 fix_pack_52
Version 7.0 fix_pack_53
Version 7.0 fix_pack_54
Version 7.0 fix_pack_56
Version 7.0 fix_pack_57
Version 7.0 fix_pack_58
Version 7.0 fix_pack_59
Version 7.0 fix_pack_60
Version 7.0 fix_pack_61
Version 7.0 fix_pack_64
Version 7.0 fix_pack_65
Version 7.0 fix_pack_66
Version 7.0 fix_pack_67
Version 7.0 fix_pack_68
Version 7.0 fix_pack_69
Version 7.0 fix_pack_70
Version 7.0 fix_pack_71
Version 7.0 fix_pack_72
Version 7.0 fix_pack_73
Version 7.0 fix_pack_75
Version 7.0 fix_pack_76
Version 7.0 fix_pack_78
Version 7.0 fix_pack_79
Version 7.0 fix_pack_80
Version 7.0 fix_pack_81
Version 7.1
Version 7.1 fix_pack_10
Version 7.1 fix_pack_11
Version 7.1 fix_pack_12
Version 7.1 fix_pack_13
Version 7.1 fix_pack_14
Version 7.1 fix_pack_15
Version 7.1 fix_pack_16
Version 7.1 fix_pack_1
Version 7.1 fix_pack_2
Version 7.1 fix_pack_3
Version 7.1 fix_pack_4
Version 7.1 fix_pack_5
Version 7.1 fix_pack_6
Version 7.1 fix_pack_7
Version 7.1 fix_pack_8
Version 7.1 fix_pack_9
Version 7.2
Version 7.2 fix_pack_1
Version 7.2 fix_pack_2
Version 7.2 fix_pack_3
Before 7.3.0

References (4)

Source: cve@mitre.org
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory

Timeline

No history available yet.