EXPOSURES › CVE-2020-7961
CVE-2020-7961
HIGH ⌖ ON CISA KEV · EXPLOITEDLiferay Portal suffered a deserialization of untrusted data vulnerability allowing remote code execution via JSON web services.
A deserialization flaw in Liferay Portal enabled remote attackers to execute arbitrary code through its JSON web services. This is a critical failure for DIB organizations because it directly compromises system integrity and allows full remote control, violating CMMC/NIST 800-171 requirements for protecting unclassified information. Organizations must ensure all Liferay deployments are patched immediately and assess their exposure to similar deserialization vulnerabilities in other components.
Shame score — A critical RCE vulnerability in a widely deployed CMS/DXP platform that was actively exploited in the wild, demonstrating severe negligence in patch management and security hygiene.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Liferay Portal contains a deserialization of untrusted data vulnerability that allows remote attackers to execute code via JSON web services.
"Liferay Portal contains a deserialization of untrusted data vulnerability that allows remote attackers to execute code via JSON web services."
"CVEs and Security Vulnerabilities - OpenCVE"
"Database CVE, CWE, CISA KEV & Vulnerability Intelligence | CVE Find"
"Latest Cybersecurity Vulnerabilities | Real-Time CVE Database"