// For flags

CVE-2023-33946

 

Severity Score

4.3
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The Object module in Liferay Portal 7.4.3.4 through 7.4.3.48, and Liferay DXP 7.4 before update 49 does properly isolate objects in difference virtual instances, which allows remote authenticated users in one virtual instance to view objects in a different virtual instance via OAuth 2 scope administration page.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2023-05-24 CVE Reserved
  • 2023-05-24 CVE Published
  • 2024-05-30 EPSS Updated
  • 2024-08-02 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-284: Improper Access Control
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Liferay
Search vendor "Liferay"
Digital Experience Platform
Search vendor "Liferay" for product "Digital Experience Platform"
7.4
Search vendor "Liferay" for product "Digital Experience Platform" and version "7.4"
-
Affected
Liferay
Search vendor "Liferay"
Digital Experience Platform
Search vendor "Liferay" for product "Digital Experience Platform"
7.4
Search vendor "Liferay" for product "Digital Experience Platform" and version "7.4"
update1
Affected
Liferay
Search vendor "Liferay"
Digital Experience Platform
Search vendor "Liferay" for product "Digital Experience Platform"
7.4
Search vendor "Liferay" for product "Digital Experience Platform" and version "7.4"
update34
Affected
Liferay
Search vendor "Liferay"
Digital Experience Platform
Search vendor "Liferay" for product "Digital Experience Platform"
7.4
Search vendor "Liferay" for product "Digital Experience Platform" and version "7.4"
update36
Affected
Liferay
Search vendor "Liferay"
Liferay Portal
Search vendor "Liferay" for product "Liferay Portal"
>= 7.4.3.4 <= 7.4.3.48
Search vendor "Liferay" for product "Liferay Portal" and version " >= 7.4.3.4 <= 7.4.3.48"
-
Affected