CVE-2025-3602

HIGH

Liferay Portal 7.4.0-7.4.3.97 and Liferay DXP 2023.Q3.1-2023.Q3.2 - Denial of Service via GraphQL Query Depth

Title source: llm
STIX 2.1

Description

Liferay Portal 7.4.0 through 7.4.3.97, and Liferay DXP 2023.Q3.1 through 2023.Q3.2, 7.4 GA through update 92, 7.3 GA through update 35, and 7.2 fix pack 8 through fix pack 20 does not limit the depth of a GraphQL queries, which allows remote attackers to perform denial-of-service (DoS) attacks on the application by executing complex queries.

Scores

CVSS v3 7.5
EPSS 0.0055
EPSS Percentile 68.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-400
Status published
Products (3)
com.liferay/com.liferay.portal.vulcan.impl 0 - 5.0.103Maven
liferay/digital_experience_platform 7.2 fix_pack_10 (13 CPE variants)
liferay/digital_experience_platform 7.3 (36 CPE variants)
Published Jun 16, 2025
Tracked Since Feb 18, 2026