← Back

CVE-2025-3594

nvd nist
Published: Jun 16, 2025Modified: Dec 12, 2025

JSON object

Loading...
8.6
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: security@liferay.com (Secondary)

Description

Path traversal vulnerability with the downloading and installation of Xuggler in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through update 34, and older unsupported versions allows remote attackers to (1) add files to arbitrary locations on the server and (2) download and execute arbitrary files from the download server via the `_com_liferay_server_admin_web_portlet_ServerAdminPortlet_jarName` parameter.

Affected (37)

2 products
Digital Experience Platform
Liferay Portal
Configuration A
37 vulnerable
Vulnerable SoftwareAffected Versions
Liferay
From 7.0 to 7.2
Version 7.3
Version 7.3 update10
Version 7.3 update11
Version 7.3 update12
Version 7.3 update13
Version 7.3 update14
Version 7.3 update15
Version 7.3 update16
Version 7.3 update17
Version 7.3 update19
Version 7.3 update1
Version 7.3 update20
Version 7.3 update21
Version 7.3 update22
Version 7.3 update23
Version 7.3 update24
Version 7.3 update25
Version 7.3 update2
Version 7.3 update3
Version 7.3 update4
Version 7.3 update5
Version 7.3 update6
Version 7.3 update7
Version 7.3 update8
Version 7.3 update9
Version 7.4 update1
Version 7.4 update2
Version 7.4 update3
Version 7.4 update4
Version 7.4 update5
Version 7.4 update6
Version 7.4 update7
Version 7.4 update8
Version 7.4 update9
Liferay
From 7.0.0 to 7.4.3.4
Version 6.2

Timeline

No history available yet.