← Back

CVE-2022-42132

nvd nist
Published: Nov 15, 2022Modified: Apr 30, 2025

JSON object

Loading...
5.9
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.2 / Impact: 3.6
Source: NVD

Description

The Test LDAP Users functionality in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.0 fix pack 102 and earlier, 7.1 before fix pack 27, 7.2 before fix pack 17, 7.3 before update 4, and DXP 7.4 GA includes the LDAP credential in the page URL when paginating through the list of users, which allows man-in-the-middle attackers or attackers with access to the request logs to see the LDAP credential.

Affected (151)

2 products
Digital Experience Platform
Liferay Portal
Configuration A
151 vulnerable
Vulnerable SoftwareAffected Versions
Liferay
Version 7.0
Version 7.0 fix_pack_100
Version 7.0 fix_pack_10
Version 7.0 fix_pack_11
Version 7.0 fix_pack_12
Version 7.0 fix_pack_13
Version 7.0 fix_pack_14
Version 7.0 fix_pack_15
Version 7.0 fix_pack_16
Version 7.0 fix_pack_17
Version 7.0 fix_pack_18
Version 7.0 fix_pack_19
Version 7.0 fix_pack_1
Version 7.0 fix_pack_20
Version 7.0 fix_pack_21
Version 7.0 fix_pack_22
Version 7.0 fix_pack_23
Version 7.0 fix_pack_24
Version 7.0 fix_pack_25
Version 7.0 fix_pack_26
Version 7.0 fix_pack_27
Version 7.0 fix_pack_28
Version 7.0 fix_pack_29
Version 7.0 fix_pack_2
Version 7.0 fix_pack_30
Version 7.0 fix_pack_31
Version 7.0 fix_pack_32
Version 7.0 fix_pack_33
Version 7.0 fix_pack_34
Version 7.0 fix_pack_35
Version 7.0 fix_pack_36
Version 7.0 fix_pack_37
Version 7.0 fix_pack_38
Version 7.0 fix_pack_39
Version 7.0 fix_pack_3
Version 7.0 fix_pack_40
Version 7.0 fix_pack_41
Version 7.0 fix_pack_42
Version 7.0 fix_pack_43
Version 7.0 fix_pack_44
Version 7.0 fix_pack_45
Version 7.0 fix_pack_46
Version 7.0 fix_pack_47
Version 7.0 fix_pack_48
Version 7.0 fix_pack_49
Version 7.0 fix_pack_4
Version 7.0 fix_pack_50
Version 7.0 fix_pack_51
Version 7.0 fix_pack_52
Version 7.0 fix_pack_53
Version 7.0 fix_pack_54
Version 7.0 fix_pack_55
Version 7.0 fix_pack_56
Version 7.0 fix_pack_57
Version 7.0 fix_pack_58
Version 7.0 fix_pack_59
Version 7.0 fix_pack_5
Version 7.0 fix_pack_60
Version 7.0 fix_pack_61
Version 7.0 fix_pack_62
Version 7.0 fix_pack_63
Version 7.0 fix_pack_64
Version 7.0 fix_pack_65
Version 7.0 fix_pack_66
Version 7.0 fix_pack_67
Version 7.0 fix_pack_68
Version 7.0 fix_pack_69
Version 7.0 fix_pack_6
Version 7.0 fix_pack_70
Version 7.0 fix_pack_71
Version 7.0 fix_pack_72
Version 7.0 fix_pack_73
Version 7.0 fix_pack_74
Version 7.0 fix_pack_75
Version 7.0 fix_pack_76
Version 7.0 fix_pack_77
Version 7.0 fix_pack_78
Version 7.0 fix_pack_79
Version 7.0 fix_pack_7
Version 7.0 fix_pack_80
Version 7.0 fix_pack_81
Version 7.0 fix_pack_82
Version 7.0 fix_pack_83
Version 7.0 fix_pack_84
Version 7.0 fix_pack_85
Version 7.0 fix_pack_86
Version 7.0 fix_pack_87
Version 7.0 fix_pack_88
Version 7.0 fix_pack_89
Version 7.0 fix_pack_8
Version 7.0 fix_pack_90
Version 7.0 fix_pack_91
Version 7.0 fix_pack_92
Version 7.0 fix_pack_93
Version 7.0 fix_pack_94
Version 7.0 fix_pack_95
Version 7.0 fix_pack_96
Version 7.0 fix_pack_97
Version 7.0 fix_pack_98
Version 7.0 fix_pack_99
Version 7.0 fix_pack_9
Version 7.1
Version 7.1 fix_pack_10
Version 7.1 fix_pack_11
Version 7.1 fix_pack_12
Version 7.1 fix_pack_13
Version 7.1 fix_pack_14
Version 7.1 fix_pack_15
Version 7.1 fix_pack_16
Version 7.1 fix_pack_17
Version 7.1 fix_pack_18
Version 7.1 fix_pack_19
Version 7.1 fix_pack_1
Version 7.1 fix_pack_20
Version 7.1 fix_pack_21
Version 7.1 fix_pack_22
Version 7.1 fix_pack_23
Version 7.1 fix_pack_24
Version 7.1 fix_pack_25
Version 7.1 fix_pack_26
Version 7.1 fix_pack_2
Version 7.1 fix_pack_3
Version 7.1 fix_pack_4
Version 7.1 fix_pack_5
Version 7.1 fix_pack_6
Version 7.1 fix_pack_7
Version 7.1 fix_pack_8
Version 7.1 fix_pack_9
Version 7.1 sp1
Version 7.2
Version 7.2 fix_pack_10
Version 7.2 fix_pack_11
Version 7.2 fix_pack_12
Version 7.2 fix_pack_13
Version 7.2 fix_pack_14
Version 7.2 fix_pack_15
Version 7.2 fix_pack_16
Version 7.2 fix_pack_1
Version 7.2 fix_pack_2
Version 7.2 fix_pack_3
Version 7.2 fix_pack_4
Version 7.2 fix_pack_5
Version 7.2 fix_pack_6
Version 7.2 fix_pack_7
Version 7.2 fix_pack_8
Version 7.2 fix_pack_9
Version 7.3
Version 7.3 fix_pack_1
Version 7.3 fix_pack_2
Version 7.4
From 7.0.0 to 7.4.3.5

References (6)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.