Authentication Bypass Vulnerability in Liferay Portal and Liferay DXP
CVE-2025-3639

2LOW

Key Information:

Vendor

Liferay

Status
Vendor
CVE Published:
18 August 2025

What is CVE-2025-3639?

This vulnerability allows unauthenticated users who possess valid credentials to bypass the usual login process on Liferay Portal and Liferay DXP. By changing the HTTP POST method to GET while Multi-Factor Authentication (MFA) is enabled, attackers can gain unauthorized access. This flaw affects multiple versions of both Liferay Portal and Liferay DXP, highlighting critical security implications for organizations using these platforms.

Affected Version(s)

DXP 7.3.10 <= 7.3.10-u36

DXP 7.4.13 <= 7.4.13-u92

DXP 2024.Q1.1 <= 2024.Q1.15

References

CVSS V4

Score:
2
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-3639 : Authentication Bypass Vulnerability in Liferay Portal and Liferay DXP