445
VMScore

CVE-2021-29040

Published: 16/05/2021 Updated: 24/05/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The JSON web services in Liferay Portal 7.3.4 and previous versions, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 20 and 7.2 before fix pack 10 may provide overly verbose error messages, which allows remote malicious users to use the contents of error messages to help launch another, more focused attacks via crafted inputs.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

liferay dxp

liferay dxp 7.0

liferay dxp 7.1

liferay dxp 7.2

liferay liferay portal