CVE-2022-42126

MEDIUM

Liferay Portal 7.3.5-7.4.3.28 and DXP 7.3-7.4 - Authenticated Improper Access Control in Asset Libraries

Title source: llm
STIX 2.1

Description

The Asset Libraries module in Liferay Portal 7.3.5 through 7.4.3.28, and Liferay DXP 7.3 before update 8, and DXP 7.4 before update 29 does not properly check permissions of asset libraries, which allows remote authenticated users to view asset libraries via the UI.

Scores

CVSS v3 4.3
EPSS 0.0014
EPSS Percentile 34.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (4)
com.liferay.portal/release.portal.bom 7.3.5 - 7.4.3.48Maven
liferay/digital_experience_platform 7.3
liferay/digital_experience_platform 7.4 (2 CPE variants)
liferay/liferay_portal 7.3.5 - 7.4.3.29
Published Nov 15, 2022
Tracked Since Feb 18, 2026