CISA description
Liferay Portal contains a deserialization of untrusted data vulnerability that allows remote attackers to execute code via JSON web services.
Liferay · Liferay Portal
Liferay Portal Deserialization of Untrusted Data Vulnerability
Liferay Portal contains a deserialization of untrusted data vulnerability that allows remote attackers to execute code via JSON web services.
Apply updates per vendor instructions.
Vulnerability data triggers these controls during assessment and continuous monitoring.