← Back

CVE-2025-3526

nvd nist
Published: Jun 16, 2025Modified: Dec 16, 2025

JSON object

Loading...
8.7
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: security@liferay.com (Secondary)

Description

SessionClicks in Liferay Portal 7.0.0 through 7.4.3.21, and Liferay DXP 7.4 GA through update 9, 7.3 GA through update 25, and older unsupported versions does not restrict the saving of request parameters in the HTTP session, which allows remote attackers to consume system memory leading to denial-of-service (DoS) conditions via crafted HTTP requests.

Affected (39)

2 products
Digital Experience Platform
Liferay Portal
Configuration A
39 vulnerable
Vulnerable SoftwareAffected Versions
Liferay
From 7.0 to 7.2
Version 7.3
Version 7.3 update10
Version 7.3 update11
Version 7.3 update12
Version 7.3 update13
Version 7.3 update14
Version 7.3 update15
Version 7.3 update16
Version 7.3 update17
Version 7.3 update18
Version 7.3 update19
Version 7.3 update1
Version 7.3 update20
Version 7.3 update21
Version 7.3 update22
Version 7.3 update23
Version 7.3 update24
Version 7.3 update25
Version 7.3 update2
Version 7.3 update3
Version 7.3 update4
Version 7.3 update5
Version 7.3 update6
Version 7.3 update7
Version 7.3 update8
Version 7.3 update9
Version 7.4
Version 7.4 update1
Version 7.4 update2
Version 7.4 update3
Version 7.4 update4
Version 7.4 update5
Version 7.4 update6
Version 7.4 update7
Version 7.4 update8
Version 7.4 update9
Liferay
From 7.0.0 to 7.4.3.21
Version 6.2

Timeline

No history available yet.