CVE-2025-43790 Object entries can be related with entries of other instances

Description

Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal and Liferay DXP allows remote authenticated users to from one virtual instance to access, create, edit, relate data/object entries/definitions to an object in a different virtual instance.

Severity

7.4 (CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N)

Affected Version(s)

  • Liferay Portal 7.4.0 through 7.4.3.124
  • Liferay DXP 2024.Q2.0 through 2024.Q2.6
  • Liferay DXP 2024.Q1.1 through 2024.Q1.12
  • Liferay DXP 7.4 GA update 92

Fixed Version(s)

Publication date: Tue, 15 Apr 2025 17:48:00 +0000

Security advisories for Liferay's enterprise offerings (e.g., Liferay DXP) are only listed here since 2023. Historial advisories are availabe in the Help Center.