S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2020-7961 Scanner

CVE-2020-7961 scanner - Code Injection vulnerability in Liferay Portal

Est. Time~30 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.1k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2020-7961
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Liferay Portal is a web-based platform that allows users to build and manage customizable digital experiences, such as websites, portals, and intranets. It is designed to simplify the development and delivery of enterprise web applications by providing a suite of tools and resources for creating rich, dynamic, and engaging online environments. With a user-friendly interface and extensive functionality, Liferay Portal is a popular choice for businesses and organizations seeking to enhance their online presence and streamline their digital processes.

However, Liferay Portal prior to 7.2.1 CE GA2 is vulnerable to a critical security issue known as CVE-2020-7961. This vulnerability arises due to improper handling of untrusted data during the deserialization of JSON web services (JSONWS), which can allow remote attackers to execute arbitrary code within the affected system. An attacker can exploit this vulnerability by crafting a specially-crafted payload and sending it to the target system, which then executes the code in the context of the application server, potentially leading to remote code execution, privilege escalation, and other forms of cyberattacks.

The exploitation of CVE-2020-7961 can result in severe consequences for organizations, compromising the confidentiality, integrity, and availability of their data and systems. Sensitive information could be stolen or damaged, and critical resources could be locked, disrupted, or destroyed. Moreover, the exploitation of this vulnerability can lead to reputational damage, regulatory fines, legal liabilities, and other non-technical impacts, affecting the viability and sustainability of the organization.

With the pro features of the s4e.io platform, you can easily and quickly learn about vulnerabilities in your digital assets. Our platform provides comprehensive scans and assessments of your web applications, network devices, and cloud services, identifying and prioritizing risks based on their severity, exploitability, and impact. Moreover, our platform offers actionable remediation guidance, custom reporting, and integration with popular security tools, enabling you to secure your digital assets effectively and efficiently. Don't wait until the next vulnerability hits - sign up for s4e.io today and take control of your cybersecurity.

 

REFERENCES

Solution Advice

To protect against CVE-2020-7961, the following precautions can be taken:

  • Update your Liferay Portal software to version 7.2.1 CE GA2 or later, which includes a patch for this vulnerability.
  • Restrict access to the JSONWS interface and ensure that it is not exposed to untrusted sources, such as the public Internet or unauthenticated users.
  • Monitor your system for suspicious activity and audit the usage of the JSONWS interface to detect any anomalous behavior.
  • Educate your staff on the risks of deserialization vulnerabilities and the importance of secure development practices, such as input validation, output encoding, and explicit type checking.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.