Critical severity9.8CISA KEVNVD Advisory· Published Mar 20, 2020· Updated Jun 17, 2026
CVE-2020-7961
CVE-2020-7961
Description
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.liferay.portal:com.liferay.portal.kernelMaven | < 4.35.3 | 4.35.3 |
Affected products
3- Liferay/Liferay Portaldescription
Patches
Vulnerability mechanics
References
10- research.checkpoint.com/2021/freakout-leveraging-newest-vulnerabilities-for-creating-a-botnet/nvdExploitThird Party Advisory
- packetstormsecurity.com/files/157254/Liferay-Portal-Java-Unmarshalling-Remote-Code-Execution.htmlnvdThird Party AdvisoryVDB EntryWEB
- packetstormsecurity.com/files/158392/Liferay-Portal-Remote-Code-Execution.htmlnvdThird Party AdvisoryVDB EntryWEB
- github.com/advisories/GHSA-w7pm-cc4v-f3g8ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-7961ghsaADVISORY
- portal.liferay.dev/learn/security/known-vulnerabilitiesnvdBroken LinkVendor AdvisoryWEB
- portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/id/117954271nvdBroken LinkVendor AdvisoryWEB
- github.com/liferay/liferay-portal/blob/7.2.1-ga2/portal-kernel/bnd.bndghsaWEB
- research.checkpoint.com/2021/freakout-leveraging-newest-vulnerabilities-for-creating-a-botnetghsaWEB
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government ResourceWEB
News mentions
0No linked articles in our index yet.