CVE-2019-16891
published 2019-10-04CVE-2019-16891: Liferay Portal CE 6.2.5 allows remote command execution because of deserialization of a JSON payload.
PriorityP268critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
45.65%
98.7th percentile
Liferay Portal CE 6.2.5 allows remote command execution because of deserialization of a JSON payload.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| liferay | liferay_portal | <= 6.0.6 | — |
| liferay | liferay_portal | — | — |
| liferay | liferay_portal | — | — |
| liferay | liferay_portal | — | — |
| liferay | liferay_portal | — | — |
| liferay | liferay_portal | — | — |
| liferay | liferay_portal | — | — |
| liferay | liferay_portal | — | — |
| liferay | liferay_portal | — | — |
| liferay | liferay_portal | — | — |
| liferay | liferay_portal | — | — |
| liferay | liferay_portal | — | — |
| liferay | liferay_portal | — | — |
| liferay | liferay_portal | — | — |
| liferay | liferay_portal | — | — |
| liferay | liferay_portal | — | — |
| liferay | liferay_portal | — | — |
| liferay | liferay_portal | — | — |
| liferay | liferay_portal | — | — |
| liferay | liferay_portal | — | — |
| liferay | liferay_portal | — | — |
| liferay | liferay_portal | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Liferay Portal Allows RCE via Deserialization of a JSON Payload
ghsa·2022-05-24
CVE-2019-16891 [CRITICAL] CWE-502 Liferay Portal Allows RCE via Deserialization of a JSON Payload
Liferay Portal Allows RCE via Deserialization of a JSON Payload
Liferay Portal CE 7.1.0 and earlier allows remote command execution because of deserialization of a JSON payload.
OSV
Liferay Portal Allows RCE via Deserialization of a JSON Payload
osv·2022-05-24
CVE-2019-16891 [CRITICAL] Liferay Portal Allows RCE via Deserialization of a JSON Payload
Liferay Portal Allows RCE via Deserialization of a JSON Payload
Liferay Portal CE 7.1.0 and earlier allows remote command execution because of deserialization of a JSON payload.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://dappsec.substack.com/p/an-advisory-for-cve-2019-16891-fromhttps://sec.vnpt.vn/2019/09/liferay-deserialization-json-deserialization-part-4/https://www.liferay.com/downloads-communityhttps://www.youtube.com/watch?v=DjMEfQW3bf0https://dappsec.substack.com/p/an-advisory-for-cve-2019-16891-fromhttps://sec.vnpt.vn/2019/09/liferay-deserialization-json-deserialization-part-4/https://www.liferay.com/downloads-communityhttps://www.youtube.com/watch?v=DjMEfQW3bf0
2019-10-04
Published