{"api_version":"1","generated_at":"2026-07-23T02:52:36+00:00","cve":"CVE-2011-1571","urls":{"html":"https://cve.report/CVE-2011-1571","api":"https://cve.report/api/cve/CVE-2011-1571.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2011-1571","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2011-1571"},"summary":{"title":"CVE-2011-1571","description":"Unspecified vulnerability in the XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote attackers to execute arbitrary commands via unknown vectors.","state":"PUBLISHED","assigner":"redhat","published_at":"2011-05-07 19:55:01","updated_at":"2026-04-29 01:13:23"},"problem_types":["NVD-CWE-noinfo","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.8","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://openwall.com/lists/oss-security/2011/03/29/1","name":"http://openwall.com/lists/oss-security/2011/03/29/1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"oss-security - CVE requests : Liferay 6.0.6","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://issues.liferay.com/secure/ReleaseNote.jspa?version=10656&styleName=Html&projectId=10952","name":"http://issues.liferay.com/secure/ReleaseNote.jspa?version=10656&styleName=Html&projectId=10952","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"],"title":"Liferay Issues - New Generation Issue Tracking","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://issues.liferay.com/browse/LPS-14726","name":"http://issues.liferay.com/browse/LPS-14726","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"],"title":"[#LPS-14726] Remote command execution in portlet \"XSL content\" - Liferay Issues","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://openwall.com/lists/oss-security/2011/04/08/5","name":"http://openwall.com/lists/oss-security/2011/04/08/5","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"oss-security - Re: CVE requests : Liferay 6.0.6","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://openwall.com/lists/oss-security/2011/04/11/9","name":"http://openwall.com/lists/oss-security/2011/04/11/9","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"oss-security - Re: CVE requests : Liferay 6.0.6","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2011-1571","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2011-1571","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2011","cve_id":"1571","vulnerable":"1","versionEndIncluding":"5.1.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"liferay","cpe5":"liferay_portal","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"community","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"1571","vulnerable":"1","versionEndIncluding":"6.0.5","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"liferay","cpe5":"liferay_portal","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"community","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T22:28:42.178Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://issues.liferay.com/browse/LPS-14726"},{"name":"[oss-security] 20110408 Re: CVE requests : Liferay 6.0.6","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://openwall.com/lists/oss-security/2011/04/08/5"},{"name":"[oss-security] 20110411 Re: CVE requests : Liferay 6.0.6","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://openwall.com/lists/oss-security/2011/04/11/9"},{"name":"[oss-security] 20110329 CVE requests : Liferay 6.0.6","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://openwall.com/lists/oss-security/2011/03/29/1"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://issues.liferay.com/secure/ReleaseNote.jspa?version=10656&styleName=Html&projectId=10952"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"Unspecified vulnerability in the XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote attackers to execute arbitrary commands via unknown vectors."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2011-05-07T19:00:00.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://issues.liferay.com/browse/LPS-14726"},{"name":"[oss-security] 20110408 Re: CVE requests : Liferay 6.0.6","tags":["mailing-list","x_refsource_MLIST"],"url":"http://openwall.com/lists/oss-security/2011/04/08/5"},{"name":"[oss-security] 20110411 Re: CVE requests : Liferay 6.0.6","tags":["mailing-list","x_refsource_MLIST"],"url":"http://openwall.com/lists/oss-security/2011/04/11/9"},{"name":"[oss-security] 20110329 CVE requests : Liferay 6.0.6","tags":["mailing-list","x_refsource_MLIST"],"url":"http://openwall.com/lists/oss-security/2011/03/29/1"},{"tags":["x_refsource_CONFIRM"],"url":"http://issues.liferay.com/secure/ReleaseNote.jspa?version=10656&styleName=Html&projectId=10952"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secalert@redhat.com","ID":"CVE-2011-1571","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Unspecified vulnerability in the XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote attackers to execute arbitrary commands via unknown vectors."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://issues.liferay.com/browse/LPS-14726","refsource":"CONFIRM","url":"http://issues.liferay.com/browse/LPS-14726"},{"name":"[oss-security] 20110408 Re: CVE requests : Liferay 6.0.6","refsource":"MLIST","url":"http://openwall.com/lists/oss-security/2011/04/08/5"},{"name":"[oss-security] 20110411 Re: CVE requests : Liferay 6.0.6","refsource":"MLIST","url":"http://openwall.com/lists/oss-security/2011/04/11/9"},{"name":"[oss-security] 20110329 CVE requests : Liferay 6.0.6","refsource":"MLIST","url":"http://openwall.com/lists/oss-security/2011/03/29/1"},{"name":"http://issues.liferay.com/secure/ReleaseNote.jspa?version=10656&styleName=Html&projectId=10952","refsource":"CONFIRM","url":"http://issues.liferay.com/secure/ReleaseNote.jspa?version=10656&styleName=Html&projectId=10952"}]}}}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2011-1571","datePublished":"2011-05-07T19:00:00.000Z","dateReserved":"2011-04-05T00:00:00.000Z","dateUpdated":"2024-09-17T00:56:46.207Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2011-05-07 19:55:01","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["NVD-CWE-noinfo","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:liferay:liferay_portal:*:*:*:*:community:*:*:*","versionStartIncluding":"5.1.0","versionEndIncluding":"5.1.2","matchCriteriaId":"8AEE2383-4164-4729-8A51-EC4F5C4CB086"},{"vulnerable":true,"criteria":"cpe:2.3:a:liferay:liferay_portal:*:*:*:*:community:*:*:*","versionStartIncluding":"6.0.0","versionEndIncluding":"6.0.5","matchCriteriaId":"36D6FB97-DA02-4BE8-9546-2676F79BD9BA"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2011","CveId":"1571","Ordinal":"1","Title":"CVE-2011-1571","CVE":"CVE-2011-1571","Year":"2011"},"notes":[{"CveYear":"2011","CveId":"1571","Ordinal":"1","NoteData":"Unspecified vulnerability in the XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote attackers to execute arbitrary commands via unknown vectors.","Type":"Description","Title":"CVE-2011-1571"},{"CveYear":"2011","CveId":"1571","Ordinal":"2","NoteData":"2011-05-07","Type":"Other","Title":"Published"}]}}}