CVE-2020-7961
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Liferay Portal Deserialization of Untrusted Data Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 100% (אחוזון 100) נכון ל-4/8/2026
- CWE
- CWE-502
מוצרים מושפעים
liferay: liferay portal
קישורים
- https://portal.liferay.dev/learn/security/known-vulnerabilities Broken LinkVendor Advisory
- https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publis… Broken LinkVendor Advisory
- https://portal.liferay.dev/learn/security/known-vulnerabilities Broken LinkVendor Advisory
- https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publis… Broken LinkVendor Advisory
- https://research.checkpoint.com/2021/freakout-leveraging-newest-vulnerabilitie… ExploitThird Party Advisory
- https://research.checkpoint.com/2021/freakout-leveraging-newest-vulnerabilitie… ExploitThird Party Advisory
- http://packetstormsecurity.com/files/157254/Liferay-Portal-Java-Unmarshalling-… Third Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/158392/Liferay-Portal-Remote-Code-Executi… Third Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/157254/Liferay-Portal-Java-Unmarshalling-… Third Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/158392/Liferay-Portal-Remote-Code-Executi… Third Party AdvisoryVDB Entry