Access Control Issue in Liferay Portal and DXP Products
CVE-2025-43768

5.1MEDIUM

Key Information:

Vendor

Liferay

Status
Vendor
CVE Published:
23 August 2025

What is CVE-2025-43768?

A security vulnerability in Liferay Portal versions 7.4.0 through 7.4.3.131 and multiple versions of Liferay DXP allows authenticated users, regardless of their permissions, to access sensitive admin user information via the JSONWS APIs. This flaw not only compromises the confidentiality of sensitive data but could also lead to unauthorized administrative actions if exploited. It is essential for users of affected versions to implement necessary patches and updates to mitigate potential risks associated with this vulnerability.

Affected Version(s)

DXP 7.4.13 <= 7.4.13-u92

DXP 2024.Q1.1 <= 2024.Q1.15

DXP 2024.Q2.0 <= 2024.Q2.13

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-43768 : Access Control Issue in Liferay Portal and DXP Products