CVE-2025-43768: High severity Liferay portal vulnerability
Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15 and 7.4 GA through update 92 allows authenticated users without any permissions to access sensitive information of admin users using JSONWS APIs.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-43768?
CVE-2025-43768 is considered a high severity vulnerability due to its potential impact on sensitive admin user information.
How do I fix CVE-2025-43768?
To fix CVE-2025-43768, upgrade Liferay Portal to version 7.4.3.132 or higher and Liferay DXP to versions above the specified vulnerable releases.
Who is affected by CVE-2025-43768?
CVE-2025-43768 affects users of Liferay Portal versions 7.4.0 to 7.4.3.131 and various releases of Liferay DXP from 2024.Q1.1 to 2024.Q4.7.
What type of vulnerability is CVE-2025-43768?
CVE-2025-43768 is an information disclosure vulnerability that allows unauthorized access to sensitive information.
What is the impact of CVE-2025-43768 on Liferay users?
The impact of CVE-2025-43768 allows authenticated users to gain access to sensitive information intended for admin users.