Loading
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).
Use CWE-502, Liferay vendor hub and Liferay Portal product page to widen CVE-2020-7961 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-62260, CVE-2025-62258 and CVE-2025-62275 for nearby disclosures in the same product family.