QID 730485

Date Published: 2022-05-12

QID 730485: Liferay Portal Denial of Service (DoS) vulnerability Vulnerability

DoS vulnerability prevents LDAP users from authenticating Liferay Portal 7.2.1 and earlier

Affected Versions:
Liferay Portal 7.2.1 and earlier

QID Detection Logic (Unauthenticated): This QID checks for vulnerable version of Liferay Portal in response banner.

Successful exploit allows attacker to prevents LDAP users from authenticating hence creating DOS

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Vendor has released patch. For more info please refer to Liferay Portal Security Advisory

    CVEs related to QID 730485

    Software Advisories
    Advisory ID Software Component Link
    Liferay Portal URL Logo portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2021-38266