8.1

CVE-2020-15842

Liferay Portal before 7.3.0, and Liferay DXP 7.0 before fix pack 90, 7.1 before fix pack 17, and 7.2 before fix pack 5, allows man-in-the-middle attackers to execute arbitrary code via crafted serialized payloads, because of insecure deserialization.

Data is provided by the National Vulnerability Database (NVD)
LiferayDigital Experience Platform Version7.0 Update-
LiferayDigital Experience Platform Version7.0 Updatefix_pack_13
LiferayDigital Experience Platform Version7.0 Updatefix_pack_14
LiferayDigital Experience Platform Version7.0 Updatefix_pack_24
LiferayDigital Experience Platform Version7.0 Updatefix_pack_25
LiferayDigital Experience Platform Version7.0 Updatefix_pack_26
LiferayDigital Experience Platform Version7.0 Updatefix_pack_27
LiferayDigital Experience Platform Version7.0 Updatefix_pack_28
LiferayDigital Experience Platform Version7.0 Updatefix_pack_3
LiferayDigital Experience Platform Version7.0 Updatefix_pack_30
LiferayDigital Experience Platform Version7.0 Updatefix_pack_33
LiferayDigital Experience Platform Version7.0 Updatefix_pack_35
LiferayDigital Experience Platform Version7.0 Updatefix_pack_36
LiferayDigital Experience Platform Version7.0 Updatefix_pack_39
LiferayDigital Experience Platform Version7.0 Updatefix_pack_40
LiferayDigital Experience Platform Version7.0 Updatefix_pack_41
LiferayDigital Experience Platform Version7.0 Updatefix_pack_42
LiferayDigital Experience Platform Version7.0 Updatefix_pack_43
LiferayDigital Experience Platform Version7.0 Updatefix_pack_44
LiferayDigital Experience Platform Version7.0 Updatefix_pack_45
LiferayDigital Experience Platform Version7.0 Updatefix_pack_46
LiferayDigital Experience Platform Version7.0 Updatefix_pack_47
LiferayDigital Experience Platform Version7.0 Updatefix_pack_48
LiferayDigital Experience Platform Version7.0 Updatefix_pack_49
LiferayDigital Experience Platform Version7.0 Updatefix_pack_50
LiferayDigital Experience Platform Version7.0 Updatefix_pack_51
LiferayDigital Experience Platform Version7.0 Updatefix_pack_52
LiferayDigital Experience Platform Version7.0 Updatefix_pack_53
LiferayDigital Experience Platform Version7.0 Updatefix_pack_54
LiferayDigital Experience Platform Version7.0 Updatefix_pack_56
LiferayDigital Experience Platform Version7.0 Updatefix_pack_57
LiferayDigital Experience Platform Version7.0 Updatefix_pack_58
LiferayDigital Experience Platform Version7.0 Updatefix_pack_59
LiferayDigital Experience Platform Version7.0 Updatefix_pack_60
LiferayDigital Experience Platform Version7.0 Updatefix_pack_61
LiferayDigital Experience Platform Version7.0 Updatefix_pack_64
LiferayDigital Experience Platform Version7.0 Updatefix_pack_65
LiferayDigital Experience Platform Version7.0 Updatefix_pack_66
LiferayDigital Experience Platform Version7.0 Updatefix_pack_67
LiferayDigital Experience Platform Version7.0 Updatefix_pack_68
LiferayDigital Experience Platform Version7.0 Updatefix_pack_69
LiferayDigital Experience Platform Version7.0 Updatefix_pack_70
LiferayDigital Experience Platform Version7.0 Updatefix_pack_71
LiferayDigital Experience Platform Version7.0 Updatefix_pack_72
LiferayDigital Experience Platform Version7.0 Updatefix_pack_73
LiferayDigital Experience Platform Version7.0 Updatefix_pack_75
LiferayDigital Experience Platform Version7.0 Updatefix_pack_76
LiferayDigital Experience Platform Version7.0 Updatefix_pack_78
LiferayDigital Experience Platform Version7.0 Updatefix_pack_79
LiferayDigital Experience Platform Version7.0 Updatefix_pack_80
LiferayDigital Experience Platform Version7.0 Updatefix_pack_81
LiferayDigital Experience Platform Version7.1 Update-
LiferayDigital Experience Platform Version7.1 Updatefix_pack_1
LiferayDigital Experience Platform Version7.1 Updatefix_pack_10
LiferayDigital Experience Platform Version7.1 Updatefix_pack_11
LiferayDigital Experience Platform Version7.1 Updatefix_pack_12
LiferayDigital Experience Platform Version7.1 Updatefix_pack_13
LiferayDigital Experience Platform Version7.1 Updatefix_pack_14
LiferayDigital Experience Platform Version7.1 Updatefix_pack_15
LiferayDigital Experience Platform Version7.1 Updatefix_pack_16
LiferayDigital Experience Platform Version7.1 Updatefix_pack_2
LiferayDigital Experience Platform Version7.1 Updatefix_pack_3
LiferayDigital Experience Platform Version7.1 Updatefix_pack_4
LiferayDigital Experience Platform Version7.1 Updatefix_pack_5
LiferayDigital Experience Platform Version7.1 Updatefix_pack_6
LiferayDigital Experience Platform Version7.1 Updatefix_pack_7
LiferayDigital Experience Platform Version7.1 Updatefix_pack_8
LiferayDigital Experience Platform Version7.1 Updatefix_pack_9
LiferayDigital Experience Platform Version7.2 Update-
LiferayDigital Experience Platform Version7.2 Updatefix_pack_1
LiferayDigital Experience Platform Version7.2 Updatefix_pack_2
LiferayDigital Experience Platform Version7.2 Updatefix_pack_3
LiferayDigital Experience Platform Version7.2 Updatefix_pack_4
LiferayDigital Experience Platform Version7.2 Updatefix_pack_5
LiferayLiferay Portal Version < 7.3.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.57% 0.659
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.1 2.2 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
cve@mitre.org 8.1 2.2 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.