First published: Mon Jul 20 2020(Updated: )
Liferay Portal before 7.3.0, and Liferay DXP 7.0 before fix pack 90, 7.1 before fix pack 17, and 7.2 before fix pack 5, allows man-in-the-middle attackers to execute arbitrary code via crafted serialized payloads, because of insecure deserialization.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Liferay 7.4 GA | =7.0 | |
Liferay 7.4 GA | =7.0-fix_pack_13 | |
Liferay 7.4 GA | =7.0-fix_pack_14 | |
Liferay 7.4 GA | =7.0-fix_pack_24 | |
Liferay 7.4 GA | =7.0-fix_pack_25 | |
Liferay 7.4 GA | =7.0-fix_pack_26 | |
Liferay 7.4 GA | =7.0-fix_pack_27 | |
Liferay 7.4 GA | =7.0-fix_pack_28 | |
Liferay 7.4 GA | =7.0-fix_pack_3\+ | |
Liferay 7.4 GA | =7.0-fix_pack_30 | |
Liferay 7.4 GA | =7.0-fix_pack_33 | |
Liferay 7.4 GA | =7.0-fix_pack_35 | |
Liferay 7.4 GA | =7.0-fix_pack_36 | |
Liferay 7.4 GA | =7.0-fix_pack_39 | |
Liferay 7.4 GA | =7.0-fix_pack_40 | |
Liferay 7.4 GA | =7.0-fix_pack_41 | |
Liferay 7.4 GA | =7.0-fix_pack_42 | |
Liferay 7.4 GA | =7.0-fix_pack_43 | |
Liferay 7.4 GA | =7.0-fix_pack_44 | |
Liferay 7.4 GA | =7.0-fix_pack_45 | |
Liferay 7.4 GA | =7.0-fix_pack_46 | |
Liferay 7.4 GA | =7.0-fix_pack_47 | |
Liferay 7.4 GA | =7.0-fix_pack_48 | |
Liferay 7.4 GA | =7.0-fix_pack_49 | |
Liferay 7.4 GA | =7.0-fix_pack_50 | |
Liferay 7.4 GA | =7.0-fix_pack_51 | |
Liferay 7.4 GA | =7.0-fix_pack_52 | |
Liferay 7.4 GA | =7.0-fix_pack_53 | |
Liferay 7.4 GA | =7.0-fix_pack_54 | |
Liferay 7.4 GA | =7.0-fix_pack_56 | |
Liferay 7.4 GA | =7.0-fix_pack_57 | |
Liferay 7.4 GA | =7.0-fix_pack_58 | |
Liferay 7.4 GA | =7.0-fix_pack_59 | |
Liferay 7.4 GA | =7.0-fix_pack_60 | |
Liferay 7.4 GA | =7.0-fix_pack_61 | |
Liferay 7.4 GA | =7.0-fix_pack_64 | |
Liferay 7.4 GA | =7.0-fix_pack_65 | |
Liferay 7.4 GA | =7.0-fix_pack_66 | |
Liferay 7.4 GA | =7.0-fix_pack_67 | |
Liferay 7.4 GA | =7.0-fix_pack_68 | |
Liferay 7.4 GA | =7.0-fix_pack_69 | |
Liferay 7.4 GA | =7.0-fix_pack_70 | |
Liferay 7.4 GA | =7.0-fix_pack_71 | |
Liferay 7.4 GA | =7.0-fix_pack_72 | |
Liferay 7.4 GA | =7.0-fix_pack_73 | |
Liferay 7.4 GA | =7.0-fix_pack_75 | |
Liferay 7.4 GA | =7.0-fix_pack_76 | |
Liferay 7.4 GA | =7.0-fix_pack_78 | |
Liferay 7.4 GA | =7.0-fix_pack_79 | |
Liferay 7.4 GA | =7.0-fix_pack_80 | |
Liferay 7.4 GA | =7.0-fix_pack_81 | |
Liferay 7.4 GA | =7.1 | |
Liferay 7.4 GA | =7.1-fix_pack_1 | |
Liferay 7.4 GA | =7.1-fix_pack_10 | |
Liferay 7.4 GA | =7.1-fix_pack_11 | |
Liferay 7.4 GA | =7.1-fix_pack_12 | |
Liferay 7.4 GA | =7.1-fix_pack_13 | |
Liferay 7.4 GA | =7.1-fix_pack_14 | |
Liferay 7.4 GA | =7.1-fix_pack_15 | |
Liferay 7.4 GA | =7.1-fix_pack_16 | |
Liferay 7.4 GA | =7.1-fix_pack_2 | |
Liferay 7.4 GA | =7.1-fix_pack_3 | |
Liferay 7.4 GA | =7.1-fix_pack_4 | |
Liferay 7.4 GA | =7.1-fix_pack_5 | |
Liferay 7.4 GA | =7.1-fix_pack_6 | |
Liferay 7.4 GA | =7.1-fix_pack_7 | |
Liferay 7.4 GA | =7.1-fix_pack_8 | |
Liferay 7.4 GA | =7.1-fix_pack_9 | |
Liferay 7.4 GA | =7.2 | |
Liferay 7.4 GA | =7.2-fix_pack_1 | |
Liferay 7.4 GA | =7.2-fix_pack_2 | |
Liferay 7.4 GA | =7.2-fix_pack_3 | |
Liferay 7.4 GA | =7.2-fix_pack_4 | |
Liferay 7.4 GA | =7.2-fix_pack_5 | |
Liferay 7.4 GA | <7.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-15842 is classified as a high severity vulnerability due to its potential for unauthorized code execution.
To fix CVE-2020-15842, upgrade to Liferay Portal version 7.3.0 or later, or apply the necessary fix packs for Liferay DXP 7.0, 7.1, and 7.2.
CVE-2020-15842 affects Liferay Portal versions prior to 7.3.0 and Liferay DXP versions before their respective fix packs.
CVE-2020-15842 allows man-in-the-middle attackers to execute arbitrary code through insecure deserialization.
CVE-2020-15842 impacts Liferay Portal before 7.3.0 and Liferay DXP versions 7.0 before fix pack 90, 7.1 before fix pack 17, and 7.2 before fix pack 5.