9.8

CVE-2019-16891

Exploit

Liferay Portal CE 6.2.5 allows remote command execution because of deserialization of a JSON payload.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LiferayLiferay Portal SwEditioncommunity Version <= 6.0.6
LiferayLiferay Portal Version6.1.0 Updateb1 SwEditioncommunity
LiferayLiferay Portal Version6.1.0 Updateb2 SwEditioncommunity
LiferayLiferay Portal Version6.1.0 Updateb3 SwEditioncommunity
LiferayLiferay Portal Version6.1.0 Updateb4 SwEditioncommunity
LiferayLiferay Portal Version6.1.0 Updatega1 SwEditioncommunity
LiferayLiferay Portal Version6.1.0 Updaterc1 SwEditioncommunity
LiferayLiferay Portal Version6.1.1 Updatega2 SwEditioncommunity
LiferayLiferay Portal Version6.1.2 Updatega3 SwEditioncommunity
LiferayLiferay Portal Version6.2.0 Updateb1 SwEditioncommunity
LiferayLiferay Portal Version6.2.0 Updateb2 SwEditioncommunity
LiferayLiferay Portal Version6.2.0 Updatega1 SwEditioncommunity
LiferayLiferay Portal Version6.2.0 Updatem1 SwEditioncommunity
LiferayLiferay Portal Version6.2.0 Updatem2 SwEditioncommunity
LiferayLiferay Portal Version6.2.0 Updatem3 SwEditioncommunity
LiferayLiferay Portal Version6.2.0 Updatem4 SwEditioncommunity
LiferayLiferay Portal Version6.2.0 Updatem5 SwEditioncommunity
LiferayLiferay Portal Version6.2.0 Updatem6 SwEditioncommunity
LiferayLiferay Portal Version6.2.0 Updaterc1 SwEditioncommunity
LiferayLiferay Portal Version6.2.0 Updaterc2 SwEditioncommunity
LiferayLiferay Portal Version6.2.0 Updaterc3 SwEditioncommunity
LiferayLiferay Portal Version6.2.0 Updaterc4 SwEditioncommunity
LiferayLiferay Portal Version6.2.0 Updaterc5 SwEditioncommunity
LiferayLiferay Portal Version6.2.0 Updaterc6 SwEditioncommunity
LiferayLiferay Portal Version6.2.1 Updatega2 SwEditioncommunity
LiferayLiferay Portal Version6.2.2 Updatega3 SwEditioncommunity
LiferayLiferay Portal Version6.2.3 Updatega4 SwEditioncommunity
LiferayLiferay Portal Version6.2.4 Updatega5 SwEditioncommunity
LiferayLiferay Portal Version6.2.5 Updatega6 SwEditioncommunity
LiferayLiferay Portal Version7.0.0 Updatea1 SwEditioncommunity
LiferayLiferay Portal Version7.0.0 Updatea2 SwEditioncommunity
LiferayLiferay Portal Version7.0.0 Updatea3 SwEditioncommunity
LiferayLiferay Portal Version7.0.0 Updatea4 SwEditioncommunity
LiferayLiferay Portal Version7.0.0 Updatea5 SwEditioncommunity
LiferayLiferay Portal Version7.0.0 Updateb1 SwEditioncommunity
LiferayLiferay Portal Version7.0.0 Updateb2 SwEditioncommunity
LiferayLiferay Portal Version7.0.0 Updateb3 SwEditioncommunity
LiferayLiferay Portal Version7.0.0 Updateb4 SwEditioncommunity
LiferayLiferay Portal Version7.0.0 Updateb5 SwEditioncommunity
LiferayLiferay Portal Version7.0.0 Updateb6 SwEditioncommunity
LiferayLiferay Portal Version7.0.0 Updateb7 SwEditioncommunity
LiferayLiferay Portal Version7.0.0 Updatega1 SwEditioncommunity
LiferayLiferay Portal Version7.0.0 Updatem1 SwEditioncommunity
LiferayLiferay Portal Version7.0.0 Updatem2 SwEditioncommunity
LiferayLiferay Portal Version7.0.0 Updatem3 SwEditioncommunity
LiferayLiferay Portal Version7.0.0 Updatem4 SwEditioncommunity
LiferayLiferay Portal Version7.0.0 Updatem5 SwEditioncommunity
LiferayLiferay Portal Version7.0.0 Updatem6 SwEditioncommunity
LiferayLiferay Portal Version7.0.0 Updatem7 SwEditioncommunity
LiferayLiferay Portal Version7.0.1 Updatega2 SwEditioncommunity
LiferayLiferay Portal Version7.0.2 Updatega3 SwEditioncommunity
LiferayLiferay Portal Version7.0.3 Updatega4 SwEditioncommunity
LiferayLiferay Portal Version7.0.4 Updatega5 SwEditioncommunity
LiferayLiferay Portal Version7.0.5 Updatega6 SwEditioncommunity
LiferayLiferay Portal Version7.0.6 Updatega7 SwEditioncommunity
LiferayLiferay Portal Version7.1.0 Updatea1 SwEditioncommunity
LiferayLiferay Portal Version7.1.0 Updatea2 SwEditioncommunity
LiferayLiferay Portal Version7.1.0 Updateb1 SwEditioncommunity
LiferayLiferay Portal Version7.1.0 Updateb2 SwEditioncommunity
LiferayLiferay Portal Version7.1.0 Updateb3 SwEditioncommunity
LiferayLiferay Portal Version7.1.0 Updatega1 SwEditioncommunity
LiferayLiferay Portal Version7.1.0 Updatem1 SwEditioncommunity
LiferayLiferay Portal Version7.1.0 Updatem2 SwEditioncommunity
LiferayLiferay Portal Version7.1.0 Updaterc1 SwEditioncommunity
LiferayLiferay Portal Version7.1.1 Updatega2 SwEditioncommunity
LiferayLiferay Portal Version7.1.2 Updatega3 SwEditioncommunity
LiferayLiferay Portal Version7.1.3 Updatega4 SwEditioncommunity
LiferayLiferay Portal Version7.2.0 Updatealpha1 SwEditioncommunity
LiferayLiferay Portal Version7.2.0 Updatebeta1 SwEditioncommunity
LiferayLiferay Portal Version7.2.0 Updatebeta2 SwEditioncommunity
LiferayLiferay Portal Version7.2.0 Updatebeta3 SwEditioncommunity
LiferayLiferay Portal Version7.2.0 Updatem2 SwEditioncommunity
LiferayLiferay Portal Version7.2.0 Updaterc1 SwEditioncommunity
LiferayLiferay Portal Version7.2.0 Updaterc2 SwEditioncommunity
LiferayLiferay Portal Version7.2.0 Updaterc3 SwEditioncommunity
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 84.81% 0.993
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.