PatchSiren

Liferay CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Liferay CVE published 2017-01-13

CVE-2010-5327

CVE-2010-5327 is a high-severity authenticated remote code execution issue in Liferay Portal. According to the NVD record, an attacker with valid credentials can abuse a crafted Velocity template to execute arbitrary shell commands. The vulnerable range is listed as Liferay Portal through 6.2.10. The NVD CVSS 3.0 vector rates this as network-exploitable with low attack complexity and high impact to confid [truncated]