Back to Labs
Security Advisory

CVE-2020-15842

About

Liferay Portal before 7.3.0, and Liferay DXP 7.0 before fix pack 90, 7.1 before fix pack 17, and 7.2 before fix pack 5, allows man-in-the-middle attackers to execute arbitrary code via crafted serialized payloads, because of insecure deserialization.

Weakness (CWE):CWE-502

Rainforest analyst review

This is an insecure-deserialization flaw in Liferay Portal and DXP, but the critical qualifier is that it's exploited by a man-in-the-middle: the attacker delivers crafted serialized payloads from a network position, not with a simple remote request. That's reflected in the elevated attack complexity.

Deserialization bugs are among the most dangerous when reachable, because they tend to yield full code execution, and this one does. What holds it back from a straightforward critical is the MITM precondition: an attacker needs to sit in the traffic path to inject the payload, which is a meaningfully higher bar than firing a packet at an open port.

We rank this a notch below where an unauthenticated deserialization RCE would land, precisely because of that network-position requirement, while still treating it as serious given the payoff. The concrete steps are enforcing transport integrity so a MITM can't inject in the first place, and inventorying Liferay and DXP instances against the specific fix-pack levels called out.

References

Related CVEs

Frequently asked questions

What is CVE-2020-15842?

Liferay Portal before 7.3.0, and Liferay DXP 7.0 before fix pack 90, 7.1 before fix pack 17, and 7.2 before fix pack 5, allows man-in-the-middle attackers to execute arbitrary code via crafted serialized payloads, because of insecure deserialization.

How severe is CVE-2020-15842?

CVE-2020-15842 carries a CVSS 3.1 base score of 8.1, rated high. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 90 out of 100, in the critical band.

How is CVE-2020-15842 exploited?

According to the CVSS vector (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H): attack vector Network, attack complexity High, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.

Which products are affected by CVE-2020-15842?

Public advisories list the following as affected: digital experience platform, liferay portal. Check the references on this page for the exact versions each vendor confirms.

How do I fix CVE-2020-15842?

Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.

Share this:LinkedInX Email