FAIL › dossier
dxp
PRODUCT· dossier confidence 20%
Liferay DXP is an enterprise digital experience platform that has suffered multiple critical SQL injection vulnerabilities in its core modules, requiring urgent patching and input validation reviews for compliance programs.
PROFILE
CategoryEnterprise Content Management / Digital Experience PlatformWhat they doLiferay DXP is a digital experience platform that enables organizations to build and manage digital experiences across multiple channels.
Websitehttps://www.liferay.com ↗
SECURITY POSTURE
The company has a documented history of critical remote code execution vulnerabilities in its core portal modules, indicating potential gaps in input validation and patch management for edge-facing components.
Notable failures
- CVE-2022-42122: SQL injection in Friendly Url module allowing arbitrary SQL execution
- CVE-2022-42120: SQL injection in Fragment module allowing arbitrary SQL execution
Patterns: repeated SQL injection vulnerabilities in core portal modules; critical RCE flaws in edge-facing URL and fragment handling components
FAILURE HISTORY · 2
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2022-11-15 | CVE-2022-42122 | critical | A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to execute arbitrary SQL commands via a crafted payload injected into the `title` field of a friendly URL. |
| 2022-11-15 | CVE-2022-42120 | critical | A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before update 17 allows attackers to execute arbitrary SQL commands via a PortletPreferences' `namespace` attribute. |
DOSSIER SOURCES
- August 2026 Critical Security Patch Update Released · blogs.oracle.com
- Oracle Critical Patch Update, August 2026 Security Update Review · blog.qualys.com
- Critical Patch Updates, Security Alerts and Bulletins - Oracle · www.oracle.com
Open questions: Current patching SLA for critical vulnerabilities · Number of active security researchers on the platform
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-23 03:49:02.901022+00:00