CVE-2020-7961
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).
- Affected products
- Liferay Portal
- Liferay Liferay Portal
- < 7.2.1
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 99.8% (100th percentile)
- Weakness
- CWE-502
- NVD status
- Analyzed
- Published
- 2020-03-20
CVE-2020-7961 at NVD
9 known exploits for CVE-2020-7961
Proof-of-concept code and exploit modules indexed by Sploitus
Exploit for Deserialization of Untrusted Data in Liferay Liferay_Portal
Exploit for Improper Restriction of Operations within the Bounds of a Memory Buffer in Apple Safari
Exploit for Deserialization of Untrusted Data in Liferay Liferay_Portal
Liferay Portal Remote Code Execution Exploit
Liferay Portal Remote Code Execution
Liferay Portal Java Unmarshalling Remote Code Execution Exploit
Liferay Portal - Java Unmarshalling via JSONWS RCE (Metasploit)
Liferay Portal Java Unmarshalling Remote Code Execution
Liferay Portal Java Unmarshalling via JSONWS RCE