FAIL › dossier
liferay
VENDOR· dossier confidence 50%
Liferay, a digital experience platform provider, has a concerning history of critical security vulnerabilities, including multiple remote code execution flaws. These incidents highlight potential weaknesses in their development processes and necessitate a thorough review of their security posture. Further investigation into their remediation practices is warranted.
PROFILE
Categorydigital-experience-platformWhat they doLiferay is a digital experience platform (DXP) provider that helps organizations create and manage websites, portals, and mobile applications. They offer a suite of tools for content management, personalization, and commerce.
SECURITY POSTURE
Liferay has a history of critical remote code execution (RCE) vulnerabilities, indicating a potential weakness in their secure development practices. Multiple vulnerabilities have been identified involving deserialization and SQL injection, suggesting a need for improved input validation and secure coding techniques.
Notable failures
- CVE-2020-7961 (RCE)
- CVE-2022-42122 (RCE - SQL Injection)
- CVE-2022-42120 (RCE - SQL Injection)
Patterns: RCE vulnerabilities; SQL injection vulnerabilities; Deserialization vulnerabilities
FAILURE HISTORY · 3
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2021-11-03 | CVE-2020-7961 | high | Liferay Portal suffered a deserialization of untrusted data vulnerability allowing remote code execution via JSON web services. |
| 2022-11-15 | CVE-2022-42122 | critical | A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to execute arbitrary SQL commands via a crafted payload injected into the `title` field of a friendly URL. |
| 2022-11-15 | CVE-2022-42120 | critical | A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before update 17 allows attackers to execute arbitrary SQL commands via a PortletPreferences' `namespace` attribute. |
SENTIMENT · TRUSTED SOURCES
synthesisneutral-0.50
Factual reporting without vendor condemnation
Neutral factual disclosure
"Liferay Portal contains a deserialization of untrusted data vulnerability that allows remote attackers to execute code via JSON web services."
Neutral database listing
"Database CVE, CWE, CISA KEV & Vulnerability Intelligence | CVE Find"
Neutral database listing
"Latest Cybersecurity Vulnerabilities | Real-Time CVE Database"
Open questions: What are Liferay's current security development lifecycle (SDLC) practices? · What remediation steps have been taken to address the identified vulnerabilities? · What is Liferay's vulnerability disclosure program?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-29 04:19:36.118358+00:00