{"api_version":"1","generated_at":"2026-07-23T03:24:27+00:00","cve":"CVE-2011-1503","urls":{"html":"https://cve.report/CVE-2011-1503","api":"https://cve.report/api/cve/CVE-2011-1503.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2011-1503","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2011-1503"},"summary":{"title":"CVE-2011-1503","description":"The XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA, when Apache Tomcat or Oracle GlassFish is used, allows remote authenticated users to read arbitrary (1) XSL and (2) XML files via a file:/// URL.","state":"PUBLISHED","assigner":"redhat","published_at":"2011-05-07 19:55:00","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-200","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"3.5","severity":"","vector":"AV:N/AC:M/Au:S/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:N/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://openwall.com/lists/oss-security/2011/03/29/1","name":"http://openwall.com/lists/oss-security/2011/03/29/1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"oss-security - CVE requests : Liferay 6.0.6","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://issues.liferay.com/secure/ReleaseNote.jspa?version=10656&styleName=Html&projectId=10952","name":"http://issues.liferay.com/secure/ReleaseNote.jspa?version=10656&styleName=Html&projectId=10952","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Release Notes","Vendor Advisory"],"title":"Liferay Issues - New Generation Issue Tracking","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://openwall.com/lists/oss-security/2011/04/08/5","name":"http://openwall.com/lists/oss-security/2011/04/08/5","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"oss-security - Re: CVE requests : Liferay 6.0.6","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://openwall.com/lists/oss-security/2011/04/11/9","name":"http://openwall.com/lists/oss-security/2011/04/11/9","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"oss-security - Re: CVE requests : Liferay 6.0.6","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://issues.liferay.com/browse/LPS-13762","name":"http://issues.liferay.com/browse/LPS-13762","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"],"title":"[#LPS-13762] XSL Content Portlet can utilize file:/// to potentially access files on the system - Liferay Issues","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2011-1503","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2011-1503","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2011","cve_id":"1503","vulnerable":"1","versionEndIncluding":"5.1.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"liferay","cpe5":"liferay_portal","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"community","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"1503","vulnerable":"1","versionEndIncluding":"5.2.3","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"liferay","cpe5":"liferay_portal","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"community","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"1503","vulnerable":"1","versionEndIncluding":"6.0.5","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"liferay","cpe5":"liferay_portal","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"community","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"1503","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"1503","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_7","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T22:28:41.764Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"[oss-security] 20110408 Re: CVE requests : Liferay 6.0.6","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://openwall.com/lists/oss-security/2011/04/08/5"},{"name":"[oss-security] 20110411 Re: CVE requests : Liferay 6.0.6","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://openwall.com/lists/oss-security/2011/04/11/9"},{"name":"[oss-security] 20110329 CVE requests : Liferay 6.0.6","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://openwall.com/lists/oss-security/2011/03/29/1"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://issues.liferay.com/browse/LPS-13762"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://issues.liferay.com/secure/ReleaseNote.jspa?version=10656&styleName=Html&projectId=10952"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"The XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA, when Apache Tomcat or Oracle GlassFish is used, allows remote authenticated users to read arbitrary (1) XSL and (2) XML files via a file:/// URL."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2011-05-07T19:00:00.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"name":"[oss-security] 20110408 Re: CVE requests : Liferay 6.0.6","tags":["mailing-list","x_refsource_MLIST"],"url":"http://openwall.com/lists/oss-security/2011/04/08/5"},{"name":"[oss-security] 20110411 Re: CVE requests : Liferay 6.0.6","tags":["mailing-list","x_refsource_MLIST"],"url":"http://openwall.com/lists/oss-security/2011/04/11/9"},{"name":"[oss-security] 20110329 CVE requests : Liferay 6.0.6","tags":["mailing-list","x_refsource_MLIST"],"url":"http://openwall.com/lists/oss-security/2011/03/29/1"},{"tags":["x_refsource_CONFIRM"],"url":"http://issues.liferay.com/browse/LPS-13762"},{"tags":["x_refsource_CONFIRM"],"url":"http://issues.liferay.com/secure/ReleaseNote.jspa?version=10656&styleName=Html&projectId=10952"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secalert@redhat.com","ID":"CVE-2011-1503","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA, when Apache Tomcat or Oracle GlassFish is used, allows remote authenticated users to read arbitrary (1) XSL and (2) XML files via a file:/// URL."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"[oss-security] 20110408 Re: CVE requests : Liferay 6.0.6","refsource":"MLIST","url":"http://openwall.com/lists/oss-security/2011/04/08/5"},{"name":"[oss-security] 20110411 Re: CVE requests : Liferay 6.0.6","refsource":"MLIST","url":"http://openwall.com/lists/oss-security/2011/04/11/9"},{"name":"[oss-security] 20110329 CVE requests : Liferay 6.0.6","refsource":"MLIST","url":"http://openwall.com/lists/oss-security/2011/03/29/1"},{"name":"http://issues.liferay.com/browse/LPS-13762","refsource":"CONFIRM","url":"http://issues.liferay.com/browse/LPS-13762"},{"name":"http://issues.liferay.com/secure/ReleaseNote.jspa?version=10656&styleName=Html&projectId=10952","refsource":"CONFIRM","url":"http://issues.liferay.com/secure/ReleaseNote.jspa?version=10656&styleName=Html&projectId=10952"}]}}}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2011-1503","datePublished":"2011-05-07T19:00:00.000Z","dateReserved":"2011-03-21T00:00:00.000Z","dateUpdated":"2024-09-17T01:50:53.554Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2011-05-07 19:55:00","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-200","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:N/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:liferay:liferay_portal:*:*:*:*:community:*:*:*","versionStartIncluding":"5.1.0","versionEndIncluding":"5.1.2","matchCriteriaId":"8AEE2383-4164-4729-8A51-EC4F5C4CB086"},{"vulnerable":true,"criteria":"cpe:2.3:a:liferay:liferay_portal:*:*:*:*:community:*:*:*","versionStartIncluding":"5.2.0","versionEndIncluding":"5.2.3","matchCriteriaId":"1D5343EC-9611-43F3-8A4F-57450BE47951"},{"vulnerable":true,"criteria":"cpe:2.3:a:liferay:liferay_portal:*:*:*:*:community:*:*:*","versionStartIncluding":"6.0.0","versionEndIncluding":"6.0.5","matchCriteriaId":"36D6FB97-DA02-4BE8-9546-2676F79BD9BA"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*","matchCriteriaId":"703AF700-7A70-47E2-BC3A-7FD03B3CA9C1"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_7:-:*:*:*:*:*:*:*","matchCriteriaId":"E33796DB-4523-4F04-B564-ADF030553D51"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2011","CveId":"1503","Ordinal":"1","Title":"CVE-2011-1503","CVE":"CVE-2011-1503","Year":"2011"},"notes":[{"CveYear":"2011","CveId":"1503","Ordinal":"1","NoteData":"The XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA, when Apache Tomcat or Oracle GlassFish is used, allows remote authenticated users to read arbitrary (1) XSL and (2) XML files via a file:/// URL.","Type":"Description","Title":"CVE-2011-1503"},{"CveYear":"2011","CveId":"1503","Ordinal":"2","NoteData":"2011-05-07","Type":"Other","Title":"Published"}]}}}