CVE-2021-33335: High severity liferay 7.4 ga vulnerability
Privilege escalation vulnerability in Liferay Portal 7.0.3 through 7.3.4, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 9 allows remote authenticated users with permission to update/edit users to take over a company administrator user account by editing the company administrator user.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-33335?
CVE-2021-33335 is a privilege escalation vulnerability in Liferay Portal 7.0.3 through 7.3.4 and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 9.
How can this vulnerability be exploited?
This vulnerability can be exploited by remote authenticated users with permission to update/edit users to take over a company administrator user account by editing the company administrator us.
What is the severity of CVE-2021-33335?
CVE-2021-33335 has a severity rating of high.
What is the Common Weakness Enumeration (CWE) ID for this vulnerability?
The CWE ID for CVE-2021-33335 is CWE-863.
Are there any known fix or mitigation steps?
To mitigate this vulnerability, it is recommended to apply the relevant fix packs provided by Liferay Portal and Liferay DXP.