Описание
Unspecified vulnerability in the XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote attackers to execute arbitrary commands via unknown vectors.
Ссылки
- Issue TrackingVendor Advisory
- Release NotesVendor Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Issue TrackingVendor Advisory
- Release NotesVendor Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 5.1.0 (включая) до 5.1.2 (включая)Версия от 6.0.0 (включая) до 6.0.5 (включая)
Одно из
cpe:2.3:a:liferay:liferay_portal:*:*:*:*:community:*:*:*
cpe:2.3:a:liferay:liferay_portal:*:*:*:*:community:*:*:*
EPSS
Процентиль: 92%
0.07397
Низкий
6.8 Medium
CVSS2
Дефекты
NVD-CWE-noinfo
Связанные уязвимости
debian
больше 14 лет назад
Unspecified vulnerability in the XSL Content portlet in Liferay Portal ...
EPSS
Процентиль: 92%
0.07397
Низкий
6.8 Medium
CVSS2
Дефекты
NVD-CWE-noinfo