8.7

CVE-2024-25606

XXE vulnerability in Liferay Portal 7.2.0 through 7.4.3.7, and older unsupported versions, and Liferay DXP 7.4 before update 4, 7.3 before update 12, 7.2 before fix pack 20, and older unsupported versions allows attackers with permission to deploy widgets/portlets/extensions to obtain sensitive information or consume system resources via the Java2WsddTask._format method.

Data is provided by the National Vulnerability Database (NVD)
LiferayDigital Experience Platform Version7.2 Update-
LiferayDigital Experience Platform Version7.2 Updatefix_pack_1
LiferayDigital Experience Platform Version7.2 Updatefix_pack_10
LiferayDigital Experience Platform Version7.2 Updatefix_pack_11
LiferayDigital Experience Platform Version7.2 Updatefix_pack_12
LiferayDigital Experience Platform Version7.2 Updatefix_pack_13
LiferayDigital Experience Platform Version7.2 Updatefix_pack_14
LiferayDigital Experience Platform Version7.2 Updatefix_pack_15
LiferayDigital Experience Platform Version7.2 Updatefix_pack_16
LiferayDigital Experience Platform Version7.2 Updatefix_pack_17
LiferayDigital Experience Platform Version7.2 Updatefix_pack_18
LiferayDigital Experience Platform Version7.2 Updatefix_pack_19
LiferayDigital Experience Platform Version7.2 Updatefix_pack_2
LiferayDigital Experience Platform Version7.2 Updatefix_pack_3
LiferayDigital Experience Platform Version7.2 Updatefix_pack_4
LiferayDigital Experience Platform Version7.2 Updatefix_pack_5
LiferayDigital Experience Platform Version7.2 Updatefix_pack_6
LiferayDigital Experience Platform Version7.2 Updatefix_pack_7
LiferayDigital Experience Platform Version7.2 Updatefix_pack_8
LiferayDigital Experience Platform Version7.2 Updatefix_pack_9
LiferayDigital Experience Platform Version7.2 Updateservice_pack_1
LiferayDigital Experience Platform Version7.2 Updateservice_pack_2
LiferayDigital Experience Platform Version7.2 Updateservice_pack_3
LiferayDigital Experience Platform Version7.2 Updateservice_pack_4
LiferayDigital Experience Platform Version7.2 Updateservice_pack_5
LiferayDigital Experience Platform Version7.2 Updateservice_pack_6
LiferayDigital Experience Platform Version7.2 Updateservice_pack_7
LiferayDigital Experience Platform Version7.3 Update-
LiferayDigital Experience Platform Version7.3 Updatefix_pack_1
LiferayDigital Experience Platform Version7.3 Updatefix_pack_2
LiferayDigital Experience Platform Version7.3 Updateservice_pack_1
LiferayDigital Experience Platform Version7.3 Updateservice_pack_3
LiferayDigital Experience Platform Version7.3 Updateupdate10
LiferayDigital Experience Platform Version7.3 Updateupdate11
LiferayDigital Experience Platform Version7.3 Updateupdate4
LiferayDigital Experience Platform Version7.3 Updateupdate5
LiferayDigital Experience Platform Version7.3 Updateupdate6
LiferayDigital Experience Platform Version7.3 Updateupdate7
LiferayDigital Experience Platform Version7.3 Updateupdate8
LiferayDigital Experience Platform Version7.3 Updateupdate9
LiferayDigital Experience Platform Version7.4 Update-
LiferayDigital Experience Platform Version7.4 Updateupdate1
LiferayDigital Experience Platform Version7.4 Updateupdate2
LiferayDigital Experience Platform Version7.4 Updateupdate3
LiferayLiferay Portal Version < 7.4.3.8
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.14% 0.34
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.7 2.3 5.8
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:H
security@liferay.com 8 1.3 6
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
CWE-611 Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.