PT-2025-34263 · Liferay · Liferay Portal+1

Published

2025-08-21

·

Updated

2025-08-21

·

CVE-2025-43754

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions: Liferay Portal versions 7.4.0 through 7.4.3.132 Liferay DXP versions 2024.Q1.1 through 2024.Q1.14 Liferay DXP versions 2024.Q2.0 through 2024.Q2.13 Liferay DXP versions 2024.Q3.0 through 2024.Q3.13 Liferay DXP versions 2024.Q4.0 through 2024.Q4.7 Liferay Portal 7.4 GA through update 92
Description: The application allows attackers to determine if an account exists by inspecting the server processing time of the login request. This is a username enumeration issue.
Recommendations: Update Liferay Portal to a version after 7.4.3.132. Update Liferay DXP to a version after 2024.Q1.14. Update Liferay DXP to a version after 2024.Q2.13. Update Liferay DXP to a version after 2024.Q3.13. Update Liferay DXP to a version after 2024.Q4.7. Update Liferay Portal to a version after update 92.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-43754
GHSA-X7P4-V8MJ-6FXX

Affected Products

Liferay Dxp
Liferay Portal