CVE-2025-43806Incorrect Authorization in Digital Experience Platform

Severity
5.3MEDIUMNVD
EPSS
0.1%
top 84.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 22
Latest updateSep 23

Description

Batch Engine in Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.7, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 does not properly check permission with import and export tasks, which allows remote authenticated users to access the exported data via the REST APIs.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Affected Packages4 packages

NVDliferay/liferay_portal7.2.07.4.3.113
CVEListV5liferay/portal7.4.07.4.3.112
NVDliferay/digital_experience_platform2023.Q4.02023.Q4.8+2
CVEListV5liferay/dxp7.4.137.4.13-u92+2

🔴Vulnerability Details

3
OSV
Liferay Portal and DXP does not properly check permission with import and export tasks2025-09-23
GHSA
Liferay Portal and DXP does not properly check permission with import and export tasks2025-09-23
CVEList
CVE-2025-43806: Batch Engine in Liferay Portal 72025-09-22

📋Vendor Advisories

1
Microsoft
`rustix::fs::Dir` iterator with the `linux_raw` backend can cause memory explosion2024-08-13
CVE-2025-43806 — Incorrect Authorization | cvebase