SB2019100409 - Deserialization of Untrusted Data in Liferay Enterprise Portal
Published: October 4, 2019 Updated: August 8, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Deserialization of Untrusted Data (CVE-ID: CVE-2019-16891)
The vulnerability allows a remote authenticated user to execute arbitrary code.
Liferay Portal CE 6.2.5 allows remote command execution because of deserialization of a JSON payload.
Remediation
Install update from vendor's website.