CVE-2023-47798

MEDIUM

Liferay Portal/DXP <7.3.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Account lockout in Liferay Portal 7.2.0 through 7.3.0, and older unsupported versions, and Liferay DXP 7.2 before fix pack 5, and older unsupported versions does not invalidate existing user sessions, which allows remote authenticated users to remain authenticated after an account has been locked.

Scores

CVSS v3 5.4
EPSS 0.0019
EPSS Percentile 40.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-384
Status published
Products (5)
com.liferay.portal/release.dxp.bom 7.2.0 - 7.2.10.fp5Maven
com.liferay.portal/release.portal.bom 7.2.0 - 7.3.1Maven
liferay/digital_experience_platform 7.2 (5 CPE variants)
liferay/digital_experience_platform < 7.2
liferay/liferay_portal 7.2.0 - 7.3.0
Published Feb 08, 2024
Tracked Since Feb 18, 2026