Information disclosure in Liferay Enterprise Portal - #VU12208

 

Information disclosure in Liferay Enterprise Portal - #VU12208

Published: April 26, 2018


Vulnerability identifier: #VU12208
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to obtain potentially sensitive information on the target system

The weakness exists due to insufficient input validation. A local attacker can submit specially crafted URL and access all files within the application's WAR folder.


Affected software

Liferay Enterprise Portal

Remediation

Update to version 7.0 CE GA6 (7.0.5) or later.


External References

Related Security Bulletins