CVE-2025-62247

EUVD-2025-35627
Missing Authorization in Collection Provider component in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 through 2025.Q1.16, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.19 allows instance users to read and select unauthorized Blueprints through the Collection Providers across instances.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 13%
Affected Products (NVD)
VendorProductVersion
liferaydigital_experience_platform
2024.q1.1 ≤
𝑥
< 2024.q1.20
liferaydigital_experience_platform
2024.q2.0 ≤
𝑥
≤ 2024.q2.13
liferaydigital_experience_platform
2024.q3.1 ≤
𝑥
≤ 2024.q3.13
liferaydigital_experience_platform
2024.q4.0 ≤
𝑥
≤ 2024.q4.7
liferayliferay_portal
7.4.0 ≤
𝑥
≤ 7.4.3.132
𝑥
= Vulnerable software versions