VULNERABILITY INTELLIGENCE
CVE-2011-1502
CVSS score4 MEDIUM
EPSS probability1.83%
CISA KEVNot currently listed
Published2011-05-07
Last modified2026-06-16
CVSS vectorAV:N/AC:L/Au:S/C:P/I:N/A:N
Description
Liferay Portal Community Edition (CE) 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote authenticated users to read arbitrary files via an entity declaration in conjunction with an entity reference, related to an XML External Entity (aka XXE) issue.
Weakness classification
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
Primary references
- secalert@redhat.com — Issue Tracking, Vendor Advisory
- secalert@redhat.com — Mailing List, Third Party Advisory
- secalert@redhat.com — Mailing List, Third Party Advisory
- secalert@redhat.com — Mailing List, Third Party Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Issue Tracking, Vendor Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Mailing List, Third Party Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Mailing List, Third Party Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Mailing List, Third Party Advisory