4.6

CVE-2025-62262

Information exposure through log file vulnerability in LDAP import feature in Liferay Portal 7.4.0 through 7.4.3.97, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows local users to view user email address in the log files.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LiferayDigital Experience Platform Version7.3 Updateservice_pack_3
LiferayDigital Experience Platform Version7.3 Updateupdate1
LiferayDigital Experience Platform Version7.3 Updateupdate10
LiferayDigital Experience Platform Version7.3 Updateupdate11
LiferayDigital Experience Platform Version7.3 Updateupdate12
LiferayDigital Experience Platform Version7.3 Updateupdate13
LiferayDigital Experience Platform Version7.3 Updateupdate14
LiferayDigital Experience Platform Version7.3 Updateupdate15
LiferayDigital Experience Platform Version7.3 Updateupdate16
LiferayDigital Experience Platform Version7.3 Updateupdate17
LiferayDigital Experience Platform Version7.3 Updateupdate18
LiferayDigital Experience Platform Version7.3 Updateupdate19
LiferayDigital Experience Platform Version7.3 Updateupdate2
LiferayDigital Experience Platform Version7.3 Updateupdate20
LiferayDigital Experience Platform Version7.3 Updateupdate21
LiferayDigital Experience Platform Version7.3 Updateupdate22
LiferayDigital Experience Platform Version7.3 Updateupdate23
LiferayDigital Experience Platform Version7.3 Updateupdate24
LiferayDigital Experience Platform Version7.3 Updateupdate25
LiferayDigital Experience Platform Version7.3 Updateupdate26
LiferayDigital Experience Platform Version7.3 Updateupdate27
LiferayDigital Experience Platform Version7.3 Updateupdate28
LiferayDigital Experience Platform Version7.3 Updateupdate29
LiferayDigital Experience Platform Version7.3 Updateupdate3
LiferayDigital Experience Platform Version7.3 Updateupdate30
LiferayDigital Experience Platform Version7.3 Updateupdate31
LiferayDigital Experience Platform Version7.3 Updateupdate32
LiferayDigital Experience Platform Version7.3 Updateupdate33
LiferayDigital Experience Platform Version7.3 Updateupdate34
LiferayDigital Experience Platform Version7.3 Updateupdate35
LiferayDigital Experience Platform Version7.3 Updateupdate36
LiferayDigital Experience Platform Version7.3 Updateupdate4
LiferayDigital Experience Platform Version7.3 Updateupdate5
LiferayDigital Experience Platform Version7.3 Updateupdate6
LiferayDigital Experience Platform Version7.3 Updateupdate7
LiferayDigital Experience Platform Version7.3 Updateupdate8
LiferayDigital Experience Platform Version7.3 Updateupdate9
LiferayDigital Experience Platform Version2023.q3.1
LiferayDigital Experience Platform Version2023.q3.2
LiferayDigital Experience Platform Version2023.q3.3
LiferayDigital Experience Platform Version2023.q3.4
LiferayLiferay Portal Version >= 7.0.0 < 7.4.3.98
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.02% 0.028
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.4 0.8 3.6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
security@liferay.com 4.6 0 0
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-532 Insertion of Sensitive Information into Log File

The product writes sensitive information to a log file.