9.8

CVE-2025-3594

Path traversal vulnerability with the downloading and installation of Xuggler in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through update 34, and older unsupported versions allows remote attackers to (1) add files to arbitrary locations on the server and (2) download and execute arbitrary files from the download server via the `_com_liferay_server_admin_web_portlet_ServerAdminPortlet_jarName` parameter.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LiferayDigital Experience Platform Version >= 7.0 <= 7.2
LiferayDigital Experience Platform Version7.3 Update-
LiferayDigital Experience Platform Version7.3 Updateupdate1
LiferayDigital Experience Platform Version7.3 Updateupdate10
LiferayDigital Experience Platform Version7.3 Updateupdate11
LiferayDigital Experience Platform Version7.3 Updateupdate12
LiferayDigital Experience Platform Version7.3 Updateupdate13
LiferayDigital Experience Platform Version7.3 Updateupdate14
LiferayDigital Experience Platform Version7.3 Updateupdate15
LiferayDigital Experience Platform Version7.3 Updateupdate16
LiferayDigital Experience Platform Version7.3 Updateupdate17
LiferayDigital Experience Platform Version7.3 Updateupdate19
LiferayDigital Experience Platform Version7.3 Updateupdate2
LiferayDigital Experience Platform Version7.3 Updateupdate20
LiferayDigital Experience Platform Version7.3 Updateupdate21
LiferayDigital Experience Platform Version7.3 Updateupdate22
LiferayDigital Experience Platform Version7.3 Updateupdate23
LiferayDigital Experience Platform Version7.3 Updateupdate24
LiferayDigital Experience Platform Version7.3 Updateupdate25
LiferayDigital Experience Platform Version7.3 Updateupdate3
LiferayDigital Experience Platform Version7.3 Updateupdate4
LiferayDigital Experience Platform Version7.3 Updateupdate5
LiferayDigital Experience Platform Version7.3 Updateupdate6
LiferayDigital Experience Platform Version7.3 Updateupdate7
LiferayDigital Experience Platform Version7.3 Updateupdate8
LiferayDigital Experience Platform Version7.3 Updateupdate9
LiferayDigital Experience Platform Version7.4 Updateupdate1
LiferayDigital Experience Platform Version7.4 Updateupdate2
LiferayDigital Experience Platform Version7.4 Updateupdate3
LiferayDigital Experience Platform Version7.4 Updateupdate4
LiferayDigital Experience Platform Version7.4 Updateupdate5
LiferayDigital Experience Platform Version7.4 Updateupdate6
LiferayDigital Experience Platform Version7.4 Updateupdate7
LiferayDigital Experience Platform Version7.4 Updateupdate8
LiferayDigital Experience Platform Version7.4 Updateupdate9
LiferayLiferay Portal Version >= 7.0.0 <= 7.4.3.4
LiferayLiferay Portal Version6.2 Update- SwEditionenterprise
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.31% 0.537
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
security@liferay.com 8.6 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.