CVE-2025-43772

HIGH

Liferay Portal 7.0.0-7.4.3.4 and Liferay DXP - Denial of Service via Unrestricted Session Parameter Storage

Title source: llm
STIX 2.1

Description

Kaleo Forms Admin in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through update 27, and older unsupported versions does not restrict the saving of request parameters in the portlet session, which allows remote attackers to consume system memory leading to denial-of-service (DoS) conditions via crafted HTTP request.

Scores

CVSS v4 7.1
EPSS 0.0057
EPSS Percentile 68.8%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-400
Status published
Products (8)
com.liferay/com.liferay.portal.workflow.kaleo.forms.web 0 - 5.0.29Maven
Liferay/DXP 6.2.0 - portal-173
Liferay/DXP 7.0.10 - de-102
Liferay/DXP 7.1.10 - dxp-28
Liferay/DXP 7.2.10 - dxp-20
Liferay/DXP 7.3.10 - 7.3.10-u27
Liferay/DXP 7.4.13 - 7.4.13-u1
Liferay/Portal 7.0.0 - 7.4.3.5
Published Sep 04, 2025
Tracked Since Feb 18, 2026