CVE-2025-43762
Java vulnerability analysis and mitigation

Overview

A vulnerability has been identified in Liferay Portal and DXP versions affecting multiple releases from 7.4.0 through 2025.Q1.1. The vulnerability (CVE-2025-43762) allows users to upload an unlimited amount of files through forms, which are stored in the document library, potentially enabling attackers to cause denial of service conditions. The issue was disclosed on March 17, 2025, and received a CVSS v4.0 base score of 5.3 (Medium) (Liferay Advisory).

Technical details

The vulnerability is classified as CWE-770 (Allocation of Resources Without Limits or Throttling). The issue stems from a lack of restrictions on file upload functionality in the forms feature, where files are stored in the document_library without proper limitations. The vulnerability has received a CVSS v4.0 vector string of CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:L/SA:L, indicating network accessibility, low attack complexity, and passive user interaction requirements (NVD).

Impact

The primary impact of this vulnerability is the potential for denial of service (DoS) attacks through unrestricted file uploads. By exploiting this vulnerability, attackers can consume storage resources in the document library, potentially affecting system availability and performance (Liferay Advisory).

Mitigation and workarounds

Fixed versions have been released to address this vulnerability. Organizations should upgrade to Liferay Portal master branch, Liferay DXP 2025.Q2.0, Liferay DXP 2025.Q1.2, or Liferay DXP 2024.Q1.15 to mitigate the issue (Liferay Advisory).

Additional resources


SourceThis report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-26866HIGH8.8
  • JavaJava
  • org.apache.hugegraph:hg-pd-core
NoYesDec 12, 2025
CVE-2025-54981HIGH7.5
  • JavaJava
  • org.apache.streampark:streampark
NoYesDec 12, 2025
CVE-2025-67721MEDIUM6.3
  • JavaJava
  • trino
NoYesDec 12, 2025
CVE-2025-53960MEDIUM5.9
  • JavaJava
  • org.apache.streampark:streampark
NoYesDec 12, 2025
CVE-2025-54947MEDIUM5.3
  • JavaJava
  • org.apache.streampark:streampark
NoYesDec 12, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management