Liferay Portal Unauthorized-Access vulnerability
BID:53185
Info
Liferay Portal Unauthorized-Access vulnerability
| Bugtraq ID: | 53185 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 20 2012 12:00AM |
| Updated: | Apr 20 2012 12:00AM |
| Credit: | Jelmer Kuperus |
| Vulnerable: |
Liferay Enterprise Portal 6.1 ce |
| Not Vulnerable: | |
Discussion
Liferay Portal Unauthorized-Access vulnerability
Liferay Portal is prone to an unauthorized-access vulnerability.
Attackers can exploit these issue to gain unauthorized access to the affected application. Successful exploits may result in a complete compromise of the application.
Liferay Portal is prone to an unauthorized-access vulnerability.
Attackers can exploit these issue to gain unauthorized access to the affected application. Successful exploits may result in a complete compromise of the application.
Exploit / POC
Liferay Portal Unauthorized-Access vulnerability
An attacker can exploit this issue through a browser.
An attacker can exploit this issue through a browser.
Solution / Fix
Liferay Portal Unauthorized-Access vulnerability
Solution:
Reports indicate these issues have been fixed. Symantec has not verified this information.
Solution:
Reports indicate these issues have been fixed. Symantec has not verified this information.
References
Liferay Portal Unauthorized-Access vulnerability
References:
References:
- Liferay Portal Product Page (Liferay)
- Specially crafted Json service request allows full control over a Liferay portal (Jelmer Kuperus)