Authentication Bypass Vulnerability in Liferay Portal and Liferay DXP
CVE-2025-3639
2LOW
What is CVE-2025-3639?
This vulnerability allows unauthenticated users who possess valid credentials to bypass the usual login process on Liferay Portal and Liferay DXP. By changing the HTTP POST method to GET while Multi-Factor Authentication (MFA) is enabled, attackers can gain unauthorized access. This flaw affects multiple versions of both Liferay Portal and Liferay DXP, highlighting critical security implications for organizations using these platforms.
Affected Version(s)
DXP 7.3.10 <= 7.3.10-u36
DXP 7.4.13 <= 7.4.13-u92
DXP 2024.Q1.1 <= 2024.Q1.15