8.7
CVE-2025-3602
- EPSS 0.12%
- Veröffentlicht 16.06.2025 13:50:04
- Zuletzt bearbeitet 16.12.2025 17:03:12
- Quelle security@liferay.com
- CVE-Watchlists
- Unerledigt
Liferay Portal 7.4.0 through 7.4.3.97, and Liferay DXP 2023.Q3.1 through 2023.Q3.2, 7.4 GA through update 92, 7.3 GA through update 35, and 7.2 fix pack 8 through fix pack 20 does not limit the depth of a GraphQL queries, which allows remote attackers to perform denial-of-service (DoS) attacks on the application by executing complex queries.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Liferay ≫ Digital Experience Platform Version >= 2023.q3.1 <= 2023.q3.2
Liferay ≫ Digital Experience Platform Version7.2 Updatefix_pack_10
Liferay ≫ Digital Experience Platform Version7.2 Updatefix_pack_11
Liferay ≫ Digital Experience Platform Version7.2 Updatefix_pack_12
Liferay ≫ Digital Experience Platform Version7.2 Updatefix_pack_13
Liferay ≫ Digital Experience Platform Version7.2 Updatefix_pack_14
Liferay ≫ Digital Experience Platform Version7.2 Updatefix_pack_15
Liferay ≫ Digital Experience Platform Version7.2 Updatefix_pack_16
Liferay ≫ Digital Experience Platform Version7.2 Updatefix_pack_17
Liferay ≫ Digital Experience Platform Version7.2 Updatefix_pack_18
Liferay ≫ Digital Experience Platform Version7.2 Updatefix_pack_19
Liferay ≫ Digital Experience Platform Version7.2 Updatefix_pack_20
Liferay ≫ Digital Experience Platform Version7.2 Updatefix_pack_8
Liferay ≫ Digital Experience Platform Version7.2 Updatefix_pack_9
Liferay ≫ Digital Experience Platform Version7.3 Update-
Liferay ≫ Digital Experience Platform Version7.3 Updatefix_pack_1
Liferay ≫ Digital Experience Platform Version7.3 Updatefix_pack_2
Liferay ≫ Digital Experience Platform Version7.3 Updateservice_pack_1
Liferay ≫ Digital Experience Platform Version7.3 Updateservice_pack_2
Liferay ≫ Digital Experience Platform Version7.3 Updateservice_pack_3
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate1
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate10
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate11
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate12
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate13
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate14
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate15
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate16
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate17
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate18
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate19
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate2
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate20
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate21
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate22
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate23
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate24
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate25
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate26
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate27
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate28
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate29
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate3
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate30
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate31
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate32
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate33
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate34
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate35
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate4
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate5
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate6
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate7
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate8
Liferay ≫ Digital Experience Platform Version7.3 Updateupdate9
Liferay ≫ Digital Experience Platform Version7.4
Liferay ≫ Liferay Portal Version >= 7.4.0 <= 7.4.3.97
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.12% | 0.312 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| security@liferay.com | 8.7 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-400 Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.