Does CVE-2016-1000027 affect Liferay?

Issue

  • Security scan shows CVE-2016-1000027 as an active vulnerability, is Liferay affected?

Environment

  • DXP 7.4

Resolution

  • CVE-2016-1000027 is known to us, and we can confirm that Liferay should not be vulnerable, as Liferay does not use the following components: HttpInvokerServiceExporter and readRemoteInvocation.
  • The vulnerability only exists if these endpoints are exposed to untrusted clients.
Was this article helpful?
1 out of 1 found this helpful