CVE-2021-38266
n/a n/a, liferay portal, digital experience platform 취약점
The Portal Security module in Liferay Portal 7.2.1 and earlier, and Liferay DXP 7.0 before fix pack 90, 7.1 before fix pack 17 and 7.2 before fix pack 5 does not correctly import users from LDAP, which allows remote attackers to prevent a legitimate user from authenticating by attempting to sign in as a user that exist in LDAP.
- 대응 우선순위
- 점검
- CVSS
- 7.5
- EPSS
- 1.73% 백분위 75.3% · 2026.08.02 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2022.03.03