EUVD-2022-5527
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).
- EUVD state
- Present in the current official mapping
- Known exploitation
- Recorded by ENISA since 3 Nov 2021. Evidence sources: cisa_kev.
- ENISA score
- 9.8 · CVSS 3.1
- Advisory evidence
- No linked advisory details stored yet
