CVE-2020-15841

HIGH

Liferay Portal <7.3.0 & Liferay DXP <7.0-7.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

Liferay Portal before 7.3.0, and Liferay DXP 7.0 before fix pack 89, 7.1 before fix pack 17, and 7.2 before fix pack 4, does not safely test a connection to a LDAP server, which allows remote attackers to obtain the LDAP server's password via the Test LDAP Connection feature.

References (2)

Core 2
Core References
Issue Tracking, Vendor Advisory x_refsource_misc
https://issues.liferay.com/browse/LPE-16928

Scores

CVSS v3 8.3
EPSS 0.0034
EPSS Percentile 56.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

Details

Status published
Products (3)
com.liferay.portal/release.dxp.bom 7.0.0 - 7.0.10.fp89Maven
com.liferay.portal/release.portal.bom 0 - 7.3.0Maven
liferay/digital_experience_platform 7.0 (48 CPE variants)
Published Jul 20, 2020
Tracked Since Feb 18, 2026