{"api_version":"1","generated_at":"2026-07-23T04:17:47+00:00","cve":"CVE-2011-1502","urls":{"html":"https://cve.report/CVE-2011-1502","api":"https://cve.report/api/cve/CVE-2011-1502.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2011-1502","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2011-1502"},"summary":{"title":"CVE-2011-1502","description":"Liferay Portal Community Edition (CE) 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote authenticated users to read arbitrary files via an entity declaration in conjunction with an entity reference, related to an XML External Entity (aka XXE) issue.","state":"PUBLISHED","assigner":"redhat","published_at":"2011-05-07 19:55:00","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-200","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4","severity":"","vector":"AV:N/AC:L/Au:S/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://openwall.com/lists/oss-security/2011/03/29/1","name":"http://openwall.com/lists/oss-security/2011/03/29/1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"oss-security - CVE requests : Liferay 6.0.6","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://issues.liferay.com/browse/LPS-14927","name":"http://issues.liferay.com/browse/LPS-14927","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"],"title":"[#LPS-14927] Remote file disclosure - Liferay Issues","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://openwall.com/lists/oss-security/2011/04/08/5","name":"http://openwall.com/lists/oss-security/2011/04/08/5","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"oss-security - Re: CVE requests : Liferay 6.0.6","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://openwall.com/lists/oss-security/2011/04/11/9","name":"http://openwall.com/lists/oss-security/2011/04/11/9","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"oss-security - Re: CVE requests : Liferay 6.0.6","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2011-1502","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2011-1502","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2011","cve_id":"1502","vulnerable":"1","versionEndIncluding":"6.0.5","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"liferay","cpe5":"liferay_portal","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"community","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T22:28:41.696Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://issues.liferay.com/browse/LPS-14927"},{"name":"[oss-security] 20110408 Re: CVE requests : Liferay 6.0.6","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://openwall.com/lists/oss-security/2011/04/08/5"},{"name":"[oss-security] 20110411 Re: CVE requests : Liferay 6.0.6","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://openwall.com/lists/oss-security/2011/04/11/9"},{"name":"[oss-security] 20110329 CVE requests : Liferay 6.0.6","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://openwall.com/lists/oss-security/2011/03/29/1"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"Liferay Portal Community Edition (CE) 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote authenticated users to read arbitrary files via an entity declaration in conjunction with an entity reference, related to an XML External Entity (aka XXE) issue."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2011-05-07T19:00:00.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://issues.liferay.com/browse/LPS-14927"},{"name":"[oss-security] 20110408 Re: CVE requests : Liferay 6.0.6","tags":["mailing-list","x_refsource_MLIST"],"url":"http://openwall.com/lists/oss-security/2011/04/08/5"},{"name":"[oss-security] 20110411 Re: CVE requests : Liferay 6.0.6","tags":["mailing-list","x_refsource_MLIST"],"url":"http://openwall.com/lists/oss-security/2011/04/11/9"},{"name":"[oss-security] 20110329 CVE requests : Liferay 6.0.6","tags":["mailing-list","x_refsource_MLIST"],"url":"http://openwall.com/lists/oss-security/2011/03/29/1"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secalert@redhat.com","ID":"CVE-2011-1502","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Liferay Portal Community Edition (CE) 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote authenticated users to read arbitrary files via an entity declaration in conjunction with an entity reference, related to an XML External Entity (aka XXE) issue."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://issues.liferay.com/browse/LPS-14927","refsource":"CONFIRM","url":"http://issues.liferay.com/browse/LPS-14927"},{"name":"[oss-security] 20110408 Re: CVE requests : Liferay 6.0.6","refsource":"MLIST","url":"http://openwall.com/lists/oss-security/2011/04/08/5"},{"name":"[oss-security] 20110411 Re: CVE requests : Liferay 6.0.6","refsource":"MLIST","url":"http://openwall.com/lists/oss-security/2011/04/11/9"},{"name":"[oss-security] 20110329 CVE requests : Liferay 6.0.6","refsource":"MLIST","url":"http://openwall.com/lists/oss-security/2011/03/29/1"}]}}}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2011-1502","datePublished":"2011-05-07T19:00:00.000Z","dateReserved":"2011-03-21T00:00:00.000Z","dateUpdated":"2024-09-16T16:27:31.488Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2011-05-07 19:55:00","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-200","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:liferay:liferay_portal:*:*:*:*:community:*:*:*","versionStartIncluding":"6.0.0","versionEndIncluding":"6.0.5","matchCriteriaId":"36D6FB97-DA02-4BE8-9546-2676F79BD9BA"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2011","CveId":"1502","Ordinal":"1","Title":"CVE-2011-1502","CVE":"CVE-2011-1502","Year":"2011"},"notes":[{"CveYear":"2011","CveId":"1502","Ordinal":"1","NoteData":"Liferay Portal Community Edition (CE) 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote authenticated users to read arbitrary files via an entity declaration in conjunction with an entity reference, related to an XML External Entity (aka XXE) issue.","Type":"Description","Title":"CVE-2011-1502"},{"CveYear":"2011","CveId":"1502","Ordinal":"2","NoteData":"2011-05-07","Type":"Other","Title":"Published"}]}}}