- Description
- SessionClicks in Liferay Portal 7.0.0 through 7.4.3.21, and Liferay DXP 7.4 GA through update 9, 7.3 GA through update 25, and older unsupported versions does not restrict the saving of request parameters in the HTTP session, which allows remote attackers to consume system memory leading to denial-of-service (DoS) conditions via crafted HTTP requests.
- Source
- security@liferay.com
- NVD status
- Awaiting Analysis
CVSS 4.0
- Type
- Secondary
- Base score
- 8.7
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- HIGH
- security@liferay.com
- CWE-400
- Hype score
- Not currently trending
🚨 Liferay Portal & DXP Vulnerability (CVE-2025-3526): Attackers can exploit SessionClicks to cause DoS conditions. Update to the latest versions to stay secure! Read more: https://t.co/jmQ5UgmR63 #Cybersecurity #Vulnerability #Liferay https://t.co/dVUkEDnSzI
@threatsbank
21 Jun 2025
122 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️ Vulnerabilidades encontradas en productos Liferay ❗CVE-2025-3526 ❗CVE-2025-3602 ➡️Más info: https://t.co/CVWg0gLSNX https://t.co/q0dl8zlU6h
@CERTpy
20 Jun 2025
227 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
🚨 Security Alert: High risk of exploitation for CVE-2025-3526 in Liferay Portal 7.0.0-7.4.3.21 & DXP 📛 Remote attackers can trigger DoS by manipulating request parameters to hog system memory! 🖥️⬇️ Patch immediately to protect your systems! #CyberSecurity #CVE
@SecAideInfo
19 Jun 2025
2 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[CVE-2025-3526: HIGH] Vulnerability in Liferay Portal & DXP versions allows attackers to trigger DoS by saving parameters in HTTP session, impacting system performance.#cve,CVE-2025-3526,#cybersecurity https://t.co/RjghowrQNw https://t.co/b6u4qw58Sk
@CveFindCom
16 Jun 2025
66 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes