CVE-2025-43772
HIGHLiferay Portal 7.0.0-7.4.3.4 and Liferay DXP - Denial of Service via Unrestricted Session Parameter Storage
Title source: llmDescription
Kaleo Forms Admin in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through update 27, and older unsupported versions does not restrict the saving of request parameters in the portlet session, which allows remote attackers to consume system memory leading to denial-of-service (DoS) conditions via crafted HTTP request.
References (1)
Core 1
Core References
Scores
CVSS v4
7.1
EPSS
0.0057
EPSS Percentile
68.8%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-400
Status
published
Products (8)
com.liferay/com.liferay.portal.workflow.kaleo.forms.web
0 - 5.0.29Maven
Liferay/DXP
6.2.0 - portal-173
Liferay/DXP
7.0.10 - de-102
Liferay/DXP
7.1.10 - dxp-28
Liferay/DXP
7.2.10 - dxp-20
Liferay/DXP
7.3.10 - 7.3.10-u27
Liferay/DXP
7.4.13 - 7.4.13-u1
Liferay/Portal
7.0.0 - 7.4.3.5
Published
Sep 04, 2025
Tracked Since
Feb 18, 2026