PT-2025-43515 · Liferay · Liferay Portal+1

Published

2025-10-23

·

Updated

2025-11-11

·

CVE-2025-62256

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Liferay Portal versions 7.3 GA through update 35 Liferay Portal versions 7.4.0 through 7.4.3.109 Liferay DXP versions 2023.Q3.1 through 2023.Q3.7 Liferay DXP versions 2023.Q4.0 through 2023.Q4.5 Liferay Portal 7.4 GA through update 92 older unsupported versions
Description The software does not properly restrict access to OpenAPI in certain circumstances, allowing remote attackers to access the OpenAPI YAML file via a crafted URL. The OpenAPI YAML file can be accessed through a specifically designed URL.
Recommendations Liferay Portal versions 7.3 GA through update 35: At the moment, there is no information about a newer version that contains a fix for this vulnerability. Liferay Portal versions 7.4.0 through 7.4.3.109: At the moment, there is no information about a newer version that contains a fix for this vulnerability. Liferay DXP versions 2023.Q3.1 through 2023.Q3.7: At the moment, there is no information about a newer version that contains a fix for this vulnerability. Liferay DXP versions 2023.Q4.0 through 2023.Q4.5: At the moment, there is no information about a newer version that contains a fix for this vulnerability. Liferay Portal 7.4 GA through update 92: At the moment, there is no information about a newer version that contains a fix for this vulnerability. older unsupported versions: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2025-62256
GHSA-F5VH-4RJ2-W8R8
GHSA-J82Q-C85J-XW4W

Affected Products

Liferay Dxp
Liferay Portal