Vulnerability record · CVE-2020-7961 · published 20 March 2020
CVE-2020-7961: Liferay Portal JSONWS deserialization allows remote code execution
Liferay · Liferay Portal
Liferay Portal before 7.2.1 CE GA2 deserializes untrusted data received through its JSON web services (JSONWS) endpoints. Because the input is not safely handled, a remote attacker can supply crafted serialized content that leads to arbitrary code execution on the server. This is a critical, network-reachable flaw in a widely deployed enterprise portal platform.
Description
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, unauthenticated remote code execution, KEV listing and near-maximum EPSS score make this an urgent patching priority.
What it is
Liferay Portal before 7.2.1 CE GA2 deserializes untrusted data received through its JSON web services (JSONWS) endpoints. Because the input is not safely handled, a remote attacker can supply crafted serialized content that leads to arbitrary code execution on the server. This is a critical, network-reachable flaw in a widely deployed enterprise portal platform.
Impact
An unauthenticated remote attacker can execute arbitrary code with the privileges of the Liferay Portal process, giving full control over the application server and any data or credentials it can reach.
Attack surface
Reached over the network through Liferay Portal's JSONWS interface; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are required.
Exploitation
The vulnerability is listed in CISA KEV (added 2021-11-03) and has an EPSS 30-day probability of 0.99905, and references include an exploit-tagged Check Point research writeup, indicating active exploitation in the wild.
What to do
- Upgrade Liferay Portal to 7.2.1 CE GA2 or later, or apply the vendor's patch for this issue.
- If immediate upgrade is not possible, restrict network access to JSONWS endpoints to trusted sources only.
- Disable or block unused JSONWS services and review exposed web service endpoints.
- Monitor vendor advisories and CISA KEV guidance for updated remediation instructions.
Detection
- Inspect web server and application logs for unusual POST requests to JSONWS endpoints, especially with serialized Java payload patterns.
- Alert on outbound network connections or process spawning from the Liferay Portal server that are not part of normal operations.
- Use the Check Point and Packet Storm proof-of-concept details to build signatures for known exploitation attempts.
- Monitor for unexpected file writes or new processes on hosts running Liferay Portal.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-7961 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Liferay Portal Deserialization of Untrusted Data Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-7961 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-7961), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.