Vulnerability record · CVE-2019-16891 · published 4 October 2019
CVE-2019-16891: Liferay Portal CE JSON deserialization remote command execution
Liferay · Liferay Portal
Liferay Portal CE 6.2.5 deserializes untrusted JSON payloads, allowing an unauthenticated remote attacker to execute commands. The flaw is a CWE-502 deserialization issue rated 9.8 critical, and public exploit write-ups and a video exist, making it a practical target for internet-facing portals.
Description
Liferay Portal CE 6.2.5 allows remote command execution because of deserialization of a JSON payload.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or interaction required, public exploit references, and a very high EPSS score make this an urgent patch.
What it is
Liferay Portal CE 6.2.5 deserializes untrusted JSON payloads, allowing an unauthenticated remote attacker to execute commands. The flaw is a CWE-502 deserialization issue rated 9.8 critical, and public exploit write-ups and a video exist, making it a practical target for internet-facing portals.
Impact
An attacker can run arbitrary commands on the portal host, leading to full compromise of confidentiality, integrity and availability of the application and its data.
Attack surface
Reachable over the network via a crafted JSON request to the portal; the CVSS vector shows no authentication and no user interaction required.
Exploitation
Not listed in CISA KEV, but EPSS is 0.447 (98.7th percentile) and multiple references are tagged Exploit, indicating public exploit material is available.
What to do
- Upgrade Liferay Portal CE to a fixed release from the official downloads page; 6.2.5 is the only version named in the record.
- If upgrade is not immediately possible, restrict network access to the portal and place it behind authentication or a WAF.
- Disable or block untrusted JSON deserialization endpoints where feasible.
- Monitor vendor advisories for the specific patched version, since the record does not list one.
Detection
- Inspect HTTP requests for JSON bodies containing serialization gadget markers or unexpected class names.
- Alert on outbound connections or process creation from the portal server that are not part of normal operation.
- Review portal logs for deserialization errors or unusual JSON payloads preceding command execution.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://dappsec.substack.com/p/an-advisory-for-cve-2019-16891-from | ExploitThird Party Advisory |
| https://sec.vnpt.vn/2019/09/liferay-deserialization-json-deserialization-part-4/ | ExploitThird Party Advisory |
| https://www.liferay.com/downloads-community | ProductRelease Notes |
| https://www.youtube.com/watch?v=DjMEfQW3bf0 | Exploit |
| https://dappsec.substack.com/p/an-advisory-for-cve-2019-16891-from | ExploitThird Party Advisory |
| https://sec.vnpt.vn/2019/09/liferay-deserialization-json-deserialization-part-4/ | ExploitThird Party Advisory |
| https://www.liferay.com/downloads-community | ProductRelease Notes |
| https://www.youtube.com/watch?v=DjMEfQW3bf0 | Exploit |
Track CVE-2019-16891 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-16891), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.