GHSA-372h-p48h-xw8q · Severity: critical · Ecosystem: maven — Liferay Portal Allows RCE via Deserialization of a JSON Payload
Liferay Portal CE 6.2.5 allows remote command execution because of deserialization of a JSON payload.
Conclusion & alert: CVE-2019-16891 is rated High Exploit Risk (83.7/100): CVSS Critical severity, with high exploitation likelihood (EPSS 45.65%, 99th percentile). Core evidence: 3 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 79.56% | 45.65% | -33.90% |
| 2 | 2026-03-13 | 73.43% | 79.56% | +6.13% |
| 3 | 2026-03-04 | — | 73.43% | — |
Full EPSS history (65 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| 7.5 | 2.0 | HIGH |
|
10.0 | 6.4 | [email protected] |
GHSA-372h-p48h-xw8q · Severity: critical · Ecosystem: maven — Liferay Portal Allows RCE via Deserialization of a JSON Payload
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| liferay | liferay_portal | <= 6.0.6 | cpe:2.3:a:liferay:liferay_portal:*:*:*:*:community:*:*:* |
| liferay | liferay_portal | 6.1.0 | cpe:2.3:a:liferay:liferay_portal:6.1.0:b1:*:*:community:*:*:* |
| liferay | liferay_portal | 6.1.0 | cpe:2.3:a:liferay:liferay_portal:6.1.0:b2:*:*:community:*:*:* |
| liferay | liferay_portal | 6.1.0 | cpe:2.3:a:liferay:liferay_portal:6.1.0:b3:*:*:community:*:*:* |
| liferay | liferay_portal | 6.1.0 | cpe:2.3:a:liferay:liferay_portal:6.1.0:b4:*:*:community:*:*:* |
| liferay | liferay_portal | 6.1.0 | cpe:2.3:a:liferay:liferay_portal:6.1.0:ga1:*:*:community:*:*:* |
| liferay | liferay_portal | 6.1.0 | cpe:2.3:a:liferay:liferay_portal:6.1.0:rc1:*:*:community:*:*:* |
| liferay | liferay_portal | 6.1.1 | cpe:2.3:a:liferay:liferay_portal:6.1.1:ga2:*:*:community:*:*:* |
| liferay | liferay_portal | 6.1.2 | cpe:2.3:a:liferay:liferay_portal:6.1.2:ga3:*:*:community:*:*:* |
| liferay | liferay_portal | 6.2.0 | cpe:2.3:a:liferay:liferay_portal:6.2.0:b1:*:*:community:*:*:* |
| liferay | liferay_portal | 6.2.0 | cpe:2.3:a:liferay:liferay_portal:6.2.0:b2:*:*:community:*:*:* |
| liferay | liferay_portal | 6.2.0 | cpe:2.3:a:liferay:liferay_portal:6.2.0:ga1:*:*:community:*:*:* |
| liferay | liferay_portal | 6.2.0 | cpe:2.3:a:liferay:liferay_portal:6.2.0:m1:*:*:community:*:*:* |
| liferay | liferay_portal | 6.2.0 | cpe:2.3:a:liferay:liferay_portal:6.2.0:m2:*:*:community:*:*:* |
| liferay | liferay_portal | 6.2.0 | cpe:2.3:a:liferay:liferay_portal:6.2.0:m3:*:*:community:*:*:* |
| liferay | liferay_portal | 6.2.0 | cpe:2.3:a:liferay:liferay_portal:6.2.0:m4:*:*:community:*:*:* |
| liferay | liferay_portal | 6.2.0 | cpe:2.3:a:liferay:liferay_portal:6.2.0:m5:*:*:community:*:*:* |
| liferay | liferay_portal | 6.2.0 | cpe:2.3:a:liferay:liferay_portal:6.2.0:m6:*:*:community:*:*:* |
| liferay | liferay_portal | 6.2.0 | cpe:2.3:a:liferay:liferay_portal:6.2.0:rc1:*:*:community:*:*:* |
| liferay | liferay_portal | 6.2.0 | cpe:2.3:a:liferay:liferay_portal:6.2.0:rc2:*:*:community:*:*:* |
| liferay | liferay_portal | 6.2.0 | cpe:2.3:a:liferay:liferay_portal:6.2.0:rc3:*:*:community:*:*:* |
| liferay | liferay_portal | 6.2.0 | cpe:2.3:a:liferay:liferay_portal:6.2.0:rc4:*:*:community:*:*:* |
| liferay | liferay_portal | 6.2.0 | cpe:2.3:a:liferay:liferay_portal:6.2.0:rc5:*:*:community:*:*:* |
| liferay | liferay_portal | 6.2.0 | cpe:2.3:a:liferay:liferay_portal:6.2.0:rc6:*:*:community:*:*:* |
| liferay | liferay_portal | 6.2.1 | cpe:2.3:a:liferay:liferay_portal:6.2.1:ga2:*:*:community:*:*:* |
| liferay | liferay_portal | 6.2.2 | cpe:2.3:a:liferay:liferay_portal:6.2.2:ga3:*:*:community:*:*:* |
| liferay | liferay_portal | 6.2.3 | cpe:2.3:a:liferay:liferay_portal:6.2.3:ga4:*:*:community:*:*:* |
| liferay | liferay_portal | 6.2.4 | cpe:2.3:a:liferay:liferay_portal:6.2.4:ga5:*:*:community:*:*:* |
| liferay | liferay_portal | 6.2.5 | cpe:2.3:a:liferay:liferay_portal:6.2.5:ga6:*:*:community:*:*:* |
| liferay | liferay_portal | 7.0.0 | cpe:2.3:a:liferay:liferay_portal:7.0.0:a1:*:*:community:*:*:* |
| liferay | liferay_portal | 7.0.0 | cpe:2.3:a:liferay:liferay_portal:7.0.0:a2:*:*:community:*:*:* |
| liferay | liferay_portal | 7.0.0 | cpe:2.3:a:liferay:liferay_portal:7.0.0:a3:*:*:community:*:*:* |
| liferay | liferay_portal | 7.0.0 | cpe:2.3:a:liferay:liferay_portal:7.0.0:a4:*:*:community:*:*:* |
| liferay | liferay_portal | 7.0.0 | cpe:2.3:a:liferay:liferay_portal:7.0.0:a5:*:*:community:*:*:* |
| liferay | liferay_portal | 7.0.0 | cpe:2.3:a:liferay:liferay_portal:7.0.0:b1:*:*:community:*:*:* |
| liferay | liferay_portal | 7.0.0 | cpe:2.3:a:liferay:liferay_portal:7.0.0:b2:*:*:community:*:*:* |
| liferay | liferay_portal | 7.0.0 | cpe:2.3:a:liferay:liferay_portal:7.0.0:b3:*:*:community:*:*:* |
| liferay | liferay_portal | 7.0.0 | cpe:2.3:a:liferay:liferay_portal:7.0.0:b4:*:*:community:*:*:* |
| liferay | liferay_portal | 7.0.0 | cpe:2.3:a:liferay:liferay_portal:7.0.0:b5:*:*:community:*:*:* |
| liferay | liferay_portal | 7.0.0 | cpe:2.3:a:liferay:liferay_portal:7.0.0:b6:*:*:community:*:*:* |
| liferay | liferay_portal | 7.0.0 | cpe:2.3:a:liferay:liferay_portal:7.0.0:b7:*:*:community:*:*:* |
| liferay | liferay_portal | 7.0.0 | cpe:2.3:a:liferay:liferay_portal:7.0.0:ga1:*:*:community:*:*:* |
| liferay | liferay_portal | 7.0.0 | cpe:2.3:a:liferay:liferay_portal:7.0.0:m1:*:*:community:*:*:* |
| liferay | liferay_portal | 7.0.0 | cpe:2.3:a:liferay:liferay_portal:7.0.0:m2:*:*:community:*:*:* |
| liferay | liferay_portal | 7.0.0 | cpe:2.3:a:liferay:liferay_portal:7.0.0:m3:*:*:community:*:*:* |
| liferay | liferay_portal | 7.0.0 | cpe:2.3:a:liferay:liferay_portal:7.0.0:m4:*:*:community:*:*:* |
| liferay | liferay_portal | 7.0.0 | cpe:2.3:a:liferay:liferay_portal:7.0.0:m5:*:*:community:*:*:* |
| liferay | liferay_portal | 7.0.0 | cpe:2.3:a:liferay:liferay_portal:7.0.0:m6:*:*:community:*:*:* |
| liferay | liferay_portal | 7.0.0 | cpe:2.3:a:liferay:liferay_portal:7.0.0:m7:*:*:community:*:*:* |
| liferay | liferay_portal | 7.0.1 | cpe:2.3:a:liferay:liferay_portal:7.0.1:ga2:*:*:community:*:*:* |
| liferay | liferay_portal | 7.0.2 | cpe:2.3:a:liferay:liferay_portal:7.0.2:ga3:*:*:community:*:*:* |
| liferay | liferay_portal | 7.0.3 | cpe:2.3:a:liferay:liferay_portal:7.0.3:ga4:*:*:community:*:*:* |
| liferay | liferay_portal | 7.0.4 | cpe:2.3:a:liferay:liferay_portal:7.0.4:ga5:*:*:community:*:*:* |
| liferay | liferay_portal | 7.0.5 | cpe:2.3:a:liferay:liferay_portal:7.0.5:ga6:*:*:community:*:*:* |
| liferay | liferay_portal | 7.0.6 | cpe:2.3:a:liferay:liferay_portal:7.0.6:ga7:*:*:community:*:*:* |
| liferay | liferay_portal | 7.1.0 | cpe:2.3:a:liferay:liferay_portal:7.1.0:a1:*:*:community:*:*:* |
| liferay | liferay_portal | 7.1.0 | cpe:2.3:a:liferay:liferay_portal:7.1.0:a2:*:*:community:*:*:* |
| liferay | liferay_portal | 7.1.0 | cpe:2.3:a:liferay:liferay_portal:7.1.0:b1:*:*:community:*:*:* |
| liferay | liferay_portal | 7.1.0 | cpe:2.3:a:liferay:liferay_portal:7.1.0:b2:*:*:community:*:*:* |
| liferay | liferay_portal | 7.1.0 | cpe:2.3:a:liferay:liferay_portal:7.1.0:b3:*:*:community:*:*:* |
| liferay | liferay_portal | 7.1.0 | cpe:2.3:a:liferay:liferay_portal:7.1.0:ga1:*:*:community:*:*:* |
| liferay | liferay_portal | 7.1.0 | cpe:2.3:a:liferay:liferay_portal:7.1.0:m1:*:*:community:*:*:* |
| liferay | liferay_portal | 7.1.0 | cpe:2.3:a:liferay:liferay_portal:7.1.0:m2:*:*:community:*:*:* |
| liferay | liferay_portal | 7.1.0 | cpe:2.3:a:liferay:liferay_portal:7.1.0:rc1:*:*:community:*:*:* |
| liferay | liferay_portal | 7.1.1 | cpe:2.3:a:liferay:liferay_portal:7.1.1:ga2:*:*:community:*:*:* |
| liferay | liferay_portal | 7.1.2 | cpe:2.3:a:liferay:liferay_portal:7.1.2:ga3:*:*:community:*:*:* |
| liferay | liferay_portal | 7.1.3 | cpe:2.3:a:liferay:liferay_portal:7.1.3:ga4:*:*:community:*:*:* |
| liferay | liferay_portal | 7.2.0 | cpe:2.3:a:liferay:liferay_portal:7.2.0:alpha1:*:*:community:*:*:* |
| liferay | liferay_portal | 7.2.0 | cpe:2.3:a:liferay:liferay_portal:7.2.0:beta1:*:*:community:*:*:* |
| liferay | liferay_portal | 7.2.0 | cpe:2.3:a:liferay:liferay_portal:7.2.0:beta2:*:*:community:*:*:* |
| liferay | liferay_portal | 7.2.0 | cpe:2.3:a:liferay:liferay_portal:7.2.0:beta3:*:*:community:*:*:* |
| liferay | liferay_portal | 7.2.0 | cpe:2.3:a:liferay:liferay_portal:7.2.0:m2:*:*:community:*:*:* |
| liferay | liferay_portal | 7.2.0 | cpe:2.3:a:liferay:liferay_portal:7.2.0:rc1:*:*:community:*:*:* |
| liferay | liferay_portal | 7.2.0 | cpe:2.3:a:liferay:liferay_portal:7.2.0:rc2:*:*:community:*:*:* |
| liferay | liferay_portal | 7.2.0 | cpe:2.3:a:liferay:liferay_portal:7.2.0:rc3:*:*:community:*:*:* |
| URL | Tags |
|---|---|
| https://dappsec.substack.com/p/an-advisory-for-cve-2019-16891-from | Exploit Third Party Advisory |
| https://sec.vnpt.vn/2019/09/liferay-deserialization-json-deserialization-part-4/ | Exploit Third Party Advisory |
| https://www.liferay.com/downloads-community | Product Release Notes |
| https://www.youtube.com/watch?v=DjMEfQW3bf0 | Exploit |