Release date:
Updated on:
Affected Systems:
Liferay, Inc. Liferay Portal 6.1
Description:
--------------------------------------------------------------------------------
Bugtraq id: 54796
Liferay Portal is a complete Portal solution. It is based on J2EE applications and uses EJB and JMS technologies.
The Liferay Portal has multiple security restriction bypass vulnerabilities. After successful exploitation, attackers can bypass certain security restrictions and perform illegal operations.
<* Source: Danilo Massa
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Liferay, Inc.
-------------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.liferay.com/