Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27602 | Liferay Portal's Incorrect Authorization vulnerability can lead to guest users to obtaining sensitive data |
Github GHSA |
GHSA-fvp7-jj9m-3qpf | Liferay Portal's Incorrect Authorization vulnerability can lead to guest users to obtaining sensitive data |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 11 Sep 2025 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Liferay
Liferay dxp Liferay portal |
|
| Vendors & Products |
Liferay
Liferay dxp Liferay portal |
Wed, 10 Sep 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 10 Sep 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Access Control vulnerability in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q2.0 through 2024.Q2.8, 2024.Q1.1 through 2024.Q1.12 and 7.4 GA through update 92 allows guest users to obtain object entries information via the API Builder. | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Liferay
Published:
Updated: 2025-09-10T19:25:57.521Z
Reserved: 2025-04-17T10:55:29.974Z
Link: CVE-2025-43784
Updated: 2025-09-10T19:25:32.981Z
Status : Awaiting Analysis
Published: 2025-09-10T19:15:41.320
Modified: 2025-09-11T17:14:10.147
Link: CVE-2025-43784
No data.
OpenCVE Enrichment
Updated: 2025-09-11T10:42:39Z
EUVD
Github GHSA