Security Advisory

CVE-2020-7961

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2020-03-20 18:16:42
Last updated 2025-10-21 23:35:47
Assigner mitre
State PUBLISHED

Description

Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).