Vulnerabilities > CVE-2024-25606 - XXE vulnerability in Liferay Digital Experience Platform

047910
CVSS 8.7 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
HIGH
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
liferay
CWE-611

Summary

XXE vulnerability in Liferay Portal 7.2.0 through 7.4.3.7, and older unsupported versions, and Liferay DXP 7.4 before update 4, 7.3 before update 12, 7.2 before fix pack 20, and older unsupported versions allows attackers with permission to deploy widgets/portlets/extensions to obtain sensitive information or consume system resources via the Java2WsddTask._format method.

Vulnerable Configurations

Part Description Count
Application
Liferay
436