Skip to content
COOEY

FAIL › dossier

liferay

VENDOR

· dossier confidence 50%

Liferay, a digital experience platform provider, has a concerning history of critical security vulnerabilities, including multiple remote code execution flaws. These incidents highlight potential weaknesses in their development processes and necessitate a thorough review of their security posture. Further investigation into their remediation practices is warranted.

PROFILE
Categorydigital-experience-platformWhat they doLiferay is a digital experience platform (DXP) provider that helps organizations create and manage websites, portals, and mobile applications. They offer a suite of tools for content management, personalization, and commerce.
SECURITY POSTURE

Liferay has a history of critical remote code execution (RCE) vulnerabilities, indicating a potential weakness in their secure development practices. Multiple vulnerabilities have been identified involving deserialization and SQL injection, suggesting a need for improved input validation and secure coding techniques.

Notable failures
  • CVE-2020-7961 (RCE)
  • CVE-2022-42122 (RCE - SQL Injection)
  • CVE-2022-42120 (RCE - SQL Injection)
Patterns: RCE vulnerabilities; SQL injection vulnerabilities; Deserialization vulnerabilities
FAILURE HISTORY · 3
DATEEVENTSEVSUMMARY
2021-11-03 CVE-2020-7961 high Liferay Portal suffered a deserialization of untrusted data vulnerability allowing remote code execution via JSON web services.
2022-11-15 CVE-2022-42122 critical A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to execute arbitrary SQL commands via a crafted payload injected into the `title` field of a friendly URL.
2022-11-15 CVE-2022-42120 critical A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before update 17 allows attackers to execute arbitrary SQL commands via a PortletPreferences' `namespace` attribute.
SENTIMENT · TRUSTED SOURCES
synthesisneutral-0.50
Factual reporting without vendor condemnation
cooey ↗neutral+0.00
Neutral factual disclosure
"Liferay Portal contains a deserialization of untrusted data vulnerability that allows remote attackers to execute code via JSON web services."
app.opencve.io ↗neutral+0.00
Neutral database listing
"CVEs and Security Vulnerabilities - OpenCVE"
Neutral database listing
"Database CVE, CWE, CISA KEV & Vulnerability Intelligence | CVE Find"
Neutral API documentation
"CVEDB API - Fast Vulnerability Lookups"
CISA ↗neutral+0.00
Neutral government advisory page
"ICS Advisories | CISA"
cve.akaoma.com ↗neutral+0.00
Neutral database listing
"Latest Cybersecurity Vulnerabilities | Real-Time CVE Database"
Open questions: What are Liferay's current security development lifecycle (SDLC) practices? · What remediation steps have been taken to address the identified vulnerabilities? · What is Liferay's vulnerability disclosure program?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-29 04:19:36.118358+00:00