CVE-2025-62256

Severity
6.9MEDIUM
EPSS
0.0%
top 96.47%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 23

Description

Liferay Portal 7.4.0 through 7.4.3.109, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.7, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not properly restrict access to OpenAPI in certain circumstances, which allows remote attackers to access the OpenAPI YAML file via a crafted URL.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Affected Packages5 packages

NVDliferay/liferay_portal7.4.07.4.3.110
CVEListV5liferay/portal7.4.07.4.3.109
CVEListV5liferay/dxp7.3.107.3.10-u35+3

🔴Vulnerability Details

3
GHSA
Liferay Portal and DXP do not properly restrict access to OpenAPI2025-10-23
CVEList
CVE-2025-62256: Liferay Portal 72025-10-23
OSV
Liferay Portal and DXP do not properly restrict access to OpenAPI2025-10-23
CVE-2025-62256 (MEDIUM CVSS 6.9) | Liferay Portal 7.4.0 through 7.4.3. | cvebase.io