8.7
CVE-2025-3526
- EPSS 0.14%
- Veröffentlicht 16.06.2025 14:18:34
- Zuletzt bearbeitet 16.12.2025 18:45:31
- Quelle security@liferay.com
- CVE-Watchlists
- Unerledigt
SessionClicks in Liferay Portal 7.0.0 through 7.4.3.21, and Liferay DXP 7.4 GA through update 9, 7.3 GA through update 25, and older unsupported versions does not restrict the saving of request parameters in the HTTP session, which allows remote attackers to consume system memory leading to denial-of-service (DoS) conditions via crafted HTTP requests.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Liferay ≫ Digital Experience Platform Version >= 7.0 <= 7.2
Liferay ≫ Digital Experience Platform Version7.3 Update-
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate1
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate10
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate11
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate12
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate13
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate14
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate15
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate16
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate17
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate18
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate19
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate2
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate20
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate21
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate22
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate23
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate24
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate25
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate3
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate4
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate5
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate6
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate7
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate8
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate9
Liferay ≫ Digital Experience Platform Version7.4 Update-
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate1
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate2
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate3
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate4
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate5
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate6
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate7
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate8
Liferay ≫ Digital Experience Platform Version7.4 Updateupdate9
Liferay ≫ Liferay Portal Version >= 7.0.0 <= 7.4.3.21
Liferay ≫ Liferay Portal Version6.2 SwEditionenterprise
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.14% | 0.34 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| security@liferay.com | 8.7 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-400 Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.