CVE-2025-62257

P

assword enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allows remote attackers to determine a user’s password even if account lockout is enabled via brute force attack.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:liferay:digital_experience_platform:*:*:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:2023.q3.0:*:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:2023.q4.0:*:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:2024.q1.1:*:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:2024.q1.2:*:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:2024.q1.3:*:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:2024.q1.4:*:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:2024.q1.5:*:*:*:*:*:*:*
cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*:*

History

10 Nov 2025, 21:37

Type Values Removed Values Added
First Time Liferay liferay Portal
Liferay
Liferay digital Experience Platform
References () https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2025-62257 - () https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2025-62257 - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
CPE cpe:2.3:a:liferay:digital_experience_platform:2024.q1.2:*:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:2024.q1.1:*:*:*:*:*:*:*
cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:2024.q1.3:*:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:*:*:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:2024.q1.5:*:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:2023.q4.0:*:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:2024.q1.4:*:*:*:*:*:*:*
cpe:2.3:a:liferay:digital_experience_platform:2023.q3.0:*:*:*:*:*:*:*

30 Oct 2025, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-30 00:15

Updated : 2025-11-10 21:37


NVD link : CVE-2025-62257

Mitre link : CVE-2025-62257

CVE.ORG link : CVE-2025-62257


JSON object : View

CWE
CWE-307

Improper Restriction of Excessive Authentication Attempts