6.3
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Description
Password enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allows remote attackers to determine a userβs password even if account lockout is enabled via brute force attack.
Basic Information
ID
CVE-2025-62257
Source
Liferay
Published
Oct 29, 2025 at 23:24
Affected Product
Vendor
Liferay
Product
Portal
Version
7.4.0
Affected Versions
Liferay Portal 7.4.0
Liferay DXP 2023.Q3.1
Liferay DXP 2023.Q4.0
Liferay DXP 2024.Q1.1
Liferay DXP 2023.Q3.1
Liferay DXP 2023.Q4.0
Liferay DXP 2024.Q1.1