CVE-2025-62262: Medium severity Liferay portal vulnerability
Information exposure through log file vulnerability in LDAP import feature in Liferay Portal 7.4.0 through 7.4.3.97, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows local users to view user email address in the log files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62262?
CVE-2025-62262 is classified as a moderate severity vulnerability due to information exposure risks.
How do I fix CVE-2025-62262?
To fix CVE-2025-62262, update Liferay Portal to version 7.4.3.98 or later, or Liferay DXP to version 2023.Q3.5 or later.
What impact does CVE-2025-62262 have on my system?
CVE-2025-62262 may allow local users to access sensitive information stored in log files.
Which Liferay versions are impacted by CVE-2025-62262?
CVE-2025-62262 affects Liferay Portal versions 7.4.0 through 7.4.3.97, and older versions, as well as Liferay DXP 2023.Q3.1 through 2023.Q3.4.
Is CVE-2025-62262 still a concern for users of older Liferay versions?
Yes, users of older and unsupported versions of Liferay are still at risk from CVE-2025-62262.