Skip to content
COOEY

EXPOSURES › CVE-2020-7961

CVE-2020-7961

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-7961 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatched

Liferay Portal suffered a deserialization of untrusted data vulnerability allowing remote code execution via JSON web services.

A deserialization flaw in Liferay Portal enabled remote attackers to execute arbitrary code through its JSON web services. This is a critical failure for DIB organizations because it directly compromises system integrity and allows full remote control, violating CMMC/NIST 800-171 requirements for protecting unclassified information. Organizations must ensure all Liferay deployments are patched immediately and assess their exposure to similar deserialization vulnerabilities in other components.

Shame score — A critical RCE vulnerability in a widely deployed CMS/DXP platform that was actively exploited in the wild, demonstrating severe negligence in patch management and security hygiene.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Liferay Portal contains a deserialization of untrusted data vulnerability that allows remote attackers to execute code via JSON web services.

SENTIMENT · TRUSTED SOURCES
synthesis neutral -0.50
Factual reporting without vendor condemnation
cooey ↗ neutral +0.00
Neutral factual disclosure
"Liferay Portal contains a deserialization of untrusted data vulnerability that allows remote attackers to execute code via JSON web services."
app.opencve.io ↗ neutral +0.00
Neutral database listing
"CVEs and Security Vulnerabilities - OpenCVE"
www.cvefind.com ↗ neutral +0.00
Neutral database listing
"Database CVE, CWE, CISA KEV & Vulnerability Intelligence | CVE Find"
cvedb.shodan.io ↗ neutral +0.00
Neutral API documentation
"CVEDB API - Fast Vulnerability Lookups"
CISA ↗ neutral +0.00
Neutral government advisory page
"ICS Advisories | CISA"
cve.akaoma.com ↗ neutral +0.00
Neutral database listing
"Latest Cybersecurity Vulnerabilities | Real-Time CVE Database"
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.