OSVDB ID: 86594

Title: Liferay Portal Organization Permission Handling Omni-Admin Password Manipulation

Info

Disclosure

Oct 23, 2012

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Oct 23, 2012

Description

Liferay Portal contains a flaw that is triggered when an error occurs during the handling of organization permissions. Due to improper access controls, a remote attacker may be able to change the omni-admin password.

Classification

Location: Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Integrity
Solution: Workaround, Patch / RCS
Exploit: Exploit Unknown
Disclosure: Vendor Verified

Solution

The vendor has released a patch to address this vulnerability. Check the vendor advisory or solution in the references section. There are no known workarounds or upgrades to correct this issue.

Products

Liferay Inc.

Liferay Portal

6.1 CE GA2 (6.1.1)

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/86594