VULNERABILITY INTELLIGENCE

CVE-2011-1502

CVSS score4 MEDIUM
EPSS probability1.83%
CISA KEVNot currently listed
Published2011-05-07
Last modified2026-06-16
CVSS vectorAV:N/AC:L/Au:S/C:P/I:N/A:N

Description

Liferay Portal Community Edition (CE) 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote authenticated users to read arbitrary files via an entity declaration in conjunction with an entity reference, related to an XML External Entity (aka XXE) issue.

Weakness classification

  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Primary references