PT-2025-44042 · Liferay · Liferay Dxp+1

Published

2025-10-27

·

Updated

2025-11-10

·

CVE-2025-62262

CVSS v4.0

4.6

Medium

VectorAV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Liferay Portal versions 7.3 GA through update 35 Liferay Portal versions 7.4.0 through 7.4.3.97 Liferay DXP versions 2023.Q3.1 through 2023.Q3.4 Liferay DXP versions 7.4 GA through update 92 Liferay Portal and DXP older unsupported versions
Description A flaw exists in the LDAP import feature that can lead to information exposure through log files. This allows local users to view user email addresses recorded in the logs.
Recommendations Update Liferay Portal to a version later than 7.4.3.97. Update Liferay DXP to a version later than 2023.Q3.4. Update Liferay Portal to a version later than update 92. Update Liferay DXP to a version later than update 35.

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

CVE-2025-62262
GHSA-CW79-FQ4F-9R96

Affected Products

Liferay Dxp
Liferay Portal