CVE-2025-3526

SessionClicks in Liferay Portal 7.0.0 through 7.4.3.21, and Liferay DXP 7.4 GA through update 9, 7.3 GA through update 25, and older unsupported versions does not restrict the saving of request parameters in the HTTP session, which allows remote attackers to consume system memory leading to denial-of-service (DoS) conditions via crafted HTTP requests.
CVSS

No CVSS.

Configurations

No configuration.

History

17 Jun 2025, 20:50

Type Values Removed Values Added
Summary
  • (es) SessionClicks en Liferay Portal 7.0.0 a 7.4.3.21, y Liferay DXP 7.4 GA a la actualización 9, 7.3 GA a la actualización 25 y versiones anteriores no compatibles no restringe el guardado de parámetros de solicitud en la sesión HTTP, lo que permite a atacantes remotos consumir memoria del sistema y generar condiciones de denegación de servicio (DoS) a través de solicitudes HTTP manipuladas.

16 Jun 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-16 15:15

Updated : 2025-06-17 20:50


NVD link : CVE-2025-3526

Mitre link : CVE-2025-3526

CVE.ORG link : CVE-2025-3526


JSON object : View

Products Affected

No product.

CWE
CWE-400

Uncontrolled Resource Consumption