Количество 2
Количество 2
CVE-2025-43786
Enumeration of ERC from object entry in Liferay Portal 7.4.0 through 7.4.3.128, and Liferay DXP 2024.Q3.0 through 2024.Q3.1, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 and 7.4 GA through update 92 allow attackers to determine existent ERC in the application by exploit the time response.
GHSA-9p7x-8c57-4pqv
Liferay Portal exposes ERC which can lead to exploit the time response attack
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2025-43786 Enumeration of ERC from object entry in Liferay Portal 7.4.0 through 7.4.3.128, and Liferay DXP 2024.Q3.0 through 2024.Q3.1, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 and 7.4 GA through update 92 allow attackers to determine existent ERC in the application by exploit the time response. | CVSS3: 5.3 | 0% Низкий | 5 месяцев назад | |
GHSA-9p7x-8c57-4pqv Liferay Portal exposes ERC which can lead to exploit the time response attack | 0% Низкий | 5 месяцев назад |
Уязвимостей на страницу