PT-2025-37278 · Liferay · Liferay Portal+2

Published

2025-09-12

·

Updated

2025-09-12

·

CVE-2025-43789

CVSS v3.1

5.3

Medium

AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Liferay Portal versions 7.4.0 through 7.4.3.119 Liferay DXP versions 2024.Q1.1 through 2024.Q1.9 Liferay DXP 7.4 GA through update 92
Description: JSON Web Services in Liferay Portal and DXP are registered and invoked directly as classes, allowing Service Access Policies to be executed. This allows for a bypass of intended security mechanisms.
Recommendations: Update Liferay Portal to a version later than 7.4.3.119. Update Liferay DXP to a version later than 2024.Q1.9. Update Liferay DXP 7.4 to a version later than update 92.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-43789
GHSA-Q86R-GWQC-JX85

Affected Products

Liferay Dxp
Liferay Dxp 7.4
Liferay Portal