Path Traversal Vulnerability in Liferay Portal and DXP
CVE-2025-3594
8.6HIGH
What is CVE-2025-3594?
A path traversal vulnerability exists in Liferay Portal and DXP versions 7.0.0 through 7.4.3.4. This weakness allows remote attackers to manipulate files on the server. By exploiting the _com_liferay_server_admin_web_portlet_ServerAdminPortlet_jarName
parameter, attackers can upload files to unauthorized locations and potentially download arbitrary files from a remote server, posing serious security risks. It is crucial for administrators to apply patches or update to secure versions to mitigate risks associated with this vulnerability.
Affected Version(s)
DXP 6.2.0
DXP 7.0.10
DXP 7.1.10