CVE-2025-43786
Liferay Portal exposes ERC which can lead to exploit the time response attack
EPSS 0.06%
Description
Enumeration of ERC from object entry in Liferay Portal 7.4.0 through 7.4.3.128, and Liferay DXP 2024.Q3.0 through 2024.Q3.1, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 and 7.4 GA through update 92 allow attackers to determine existent ERC in the application by exploit the time response.
How to fix CVE-2025-43786
To remediate CVE-2025-43786, upgrade the affected package to a fixed version below.
- Maven/com.liferay:com.liferay.headless.admin.workflow.impl—upgrade to 5.0.83 or later
- —upgrade to 5.0.127 or later
- —upgrade to 11.0.1 or later
Is CVE-2025-43786 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- >= 5.0.4, < 5.0.83
- >= 5.0.7, < 5.0.127
- >= 7.0.1, < 11.0.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |