CVE-2020-7961
CVE Published | 2020-03-20 |
---|---|
Related CWE(s) | CWE-502: Deserialization of Untrusted Data |
Related Vendor(s) | liferay |
Related Product(s) | liferay_portal |
Exploitation Reported (CISA KEV) | 2021-11-03 |
CVSS 3 Base Score | 9.8 (CRITICAL) |
CVSS 3 Attack Complexity | LOW |
CVSS 3 Attack Vector | NETWORK |
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).
Cyber Threat Graph Context
Explore how this CVE relates to the wider threat graph