PT-2025-37278 · Liferay · Liferay Portal+2
Published
2025-09-12
·
Updated
2025-09-12
·
CVE-2025-43789
CVSS v3.1
5.3
Medium
| AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Liferay Portal versions 7.4.0 through 7.4.3.119
Liferay DXP versions 2024.Q1.1 through 2024.Q1.9
Liferay DXP 7.4 GA through update 92
Description:
JSON Web Services in Liferay Portal and DXP are registered and invoked directly as classes, allowing Service Access Policies to be executed. This allows for a bypass of intended security mechanisms.
Recommendations:
Update Liferay Portal to a version later than 7.4.3.119.
Update Liferay DXP to a version later than 2024.Q1.9.
Update Liferay DXP 7.4 to a version later than update 92.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Liferay Dxp
Liferay Dxp 7.4
Liferay Portal