CVE-2025-43768
Java vulnerability analysis and mitigation

Overview

CVE-2025-43768 is an information disclosure vulnerability in Liferay Portal and Liferay DXP that allows authenticated users with low-level permissions to access sensitive information belonging to admin users via JSONWS APIs. It affects Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15, and 7.4 GA through update 92. The vulnerability was published on August 23, 2025, and a patch was made available the same day. It carries a CVSS v3.1 base score of 7.7 (High) and a CVSS v4.0 base score of 5.1 (Medium) (GitHub Advisory, Red Hat).

Technical details

The root cause is classified as CWE-201 (Insertion of Sensitive Information Into Sent Data), where the JSONWS API endpoints in Liferay Portal and DXP transmit sensitive administrative user data to actors who should not have access to it. An authenticated attacker with minimal (low-level) privileges can craft API requests to JSONWS endpoints that return sensitive information about admin users, exploiting the lack of proper authorization checks on those endpoints. The vulnerability requires no special configuration or elevated privileges beyond a basic authenticated session, and no user interaction from an administrator is needed. A fix commit is available in the liferay-portal repository (efdbdbc) and tracked under Liferay issue LPE-18154 (GitHub Advisory).

Impact

Successful exploitation results in unauthorized disclosure of sensitive administrative user information, including data that should be restricted to privileged accounts. While there is no integrity or availability impact, the exposed information could be leveraged for targeted attacks, privilege escalation attempts, or reconnaissance against the affected Liferay instance. The changed scope in the CVSS v3.1 rating indicates that the impact extends beyond the directly vulnerable component, potentially affecting other systems or users within the environment (GitHub Advisory, Red Hat).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.034% (0.000340), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires only a low-privilege authenticated account, which lowers the barrier for any attacker who can register or obtain credentials on the target platform.

Exploitation steps

  1. Reconnaissance: Identify internet-facing Liferay Portal or DXP instances running affected versions (Portal 7.4.0–7.4.3.131 or DXP 2024.Q4.0–2024.Q4.7, 2024.Q3.1–2024.Q3.13, 2024.Q2.0–2024.Q2.13, 2024.Q1.1–2024.Q1.15, or 7.4 GA–update 92) using tools like Shodan or Censys.
  2. Obtain low-privilege credentials: Register or obtain any valid authenticated account on the target Liferay instance — no special permissions are required.
  3. Identify JSONWS API endpoints: Browse to the Liferay JSONWS API explorer (typically at /api/jsonws) to enumerate available API methods, focusing on those that return user-related data.
  4. Craft malicious API request: Send authenticated HTTP requests to JSONWS API endpoints that expose admin user information, such as user account details, email addresses, or other sensitive fields that should be restricted to administrators.
  5. Collect sensitive data: Parse the API responses to extract sensitive administrative user information for use in further targeted attacks or reconnaissance (GitHub Advisory).

Indicators of compromise

  • Network: Unusual or high-volume authenticated HTTP GET/POST requests to /api/jsonws endpoints from low-privilege user accounts; requests querying user-related API methods (e.g., user/get-user-by-id, user/get-users) from accounts that do not normally access these endpoints.
  • Logs: Liferay access logs showing repeated JSONWS API calls by non-administrative users, particularly to endpoints returning user profile or account data; anomalous API access patterns outside of normal business hours.
  • Application Logs: Entries in Liferay's portal logs indicating API calls to user management services by accounts with no assigned roles or permissions.

Mitigation and workarounds

Liferay has released a patch addressing this vulnerability; for Liferay Portal, upgrade to version 7.4.3.132 or later, and for the Maven package com.liferay.portal:com.liferay.portal.impl, upgrade to version 108.1.1 or later. For Liferay DXP, upgrade to 2024.Q1.16+, 2024.Q4.8+, or the next available fixed quarterly release. As a temporary workaround if immediate patching is not possible, restrict or disable JSONWS API access at the network or application layer, implement strict access controls, and audit existing user permissions. Monitoring and auditing API access logs is also recommended (GitHub Advisory, Liferay Advisory).

Community reactions

The vulnerability was noted by automated CVE tracking accounts on X (formerly Twitter) shortly after disclosure. Red Hat published a security advisory tracking the CVE. No significant researcher commentary, vendor blog posts, or major media coverage has been identified beyond standard vulnerability database entries (Red Hat).

Additional resources


SourceThis report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-73644CRITICAL9.6
  • Java logoJava
  • org.openidentityplatform.opendj:opendj-server-legacy
NoYesAug 13, 2026
CVE-2026-73507HIGH7.5
  • Java logoJava
  • io.netty:netty-codec-xml
NoYesAug 13, 2026
CVE-2026-49989HIGH7.1
  • Java logoJava
  • io.crate:crate
NoYesAug 14, 2026
CVE-2026-53660HIGH7
  • Java logoJava
  • org.openidentityplatform.openam:openam-core
NoYesAug 14, 2026
CVE-2026-73508MEDIUM5.3
  • Java logoJava
  • keycloak-fips-26.7
NoYesAug 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management