Account lockout in Liferay Portal 7.2.0 through 7.3.0, and older...
Vulnerability Description
Account lockout in Liferay Portal 7.2.0 through 7.3.0, and older unsupported versions, and Liferay DXP 7.2 before fix pack 5, and older unsupported versions does not invalidate existing user sessions, which allows remote authenticated users to remain authenticated after an account has been locked.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-47798
Credits & Attribution
No credits recorded in the NVD database.
More from Liferay
View All →Affected Vendor
Liferay
View all reports →