Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27584 | Liferay Portal exposes ERC which can lead to exploit the time response attack |
Github GHSA |
GHSA-9p7x-8c57-4pqv | Liferay Portal exposes ERC which can lead to exploit the time response attack |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 11 Sep 2025 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Liferay
Liferay dxp Liferay portal |
|
| Vendors & Products |
Liferay
Liferay dxp Liferay portal |
Wed, 10 Sep 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Sep 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Enumeration of ERC from object entry in Liferay Portal 7.4.0 through 7.4.3.128, and Liferay DXP 2024.Q3.0 through 2024.Q3.1, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 and 7.4 GA through update 92 allow attackers to determine existent ERC in the application by exploit the time response. | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Liferay
Published:
Updated: 2025-09-10T15:57:41.835Z
Reserved: 2025-04-17T10:55:29.974Z
Link: CVE-2025-43786
Updated: 2025-09-10T15:57:39.267Z
Status : Awaiting Analysis
Published: 2025-09-09T20:15:40.230
Modified: 2025-09-11T17:14:25.240
Link: CVE-2025-43786
No data.
OpenCVE Enrichment
Updated: 2025-09-11T10:43:00Z
EUVD
Github GHSA