We found results for “”
CVE-2025-43814
Good to know:
Date: September 22, 2025
In Liferay Portal 7.4.0 through 7.4.3.112, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions the audit events records a user’s password reminder answer, which allows remote authenticated users to obtain a user’s password reminder answer via the audit events.
Severity Score
Related Resources (7)
Severity Score
Weakness Type (CWE)
Insertion of Sensitive Information Into Sent Data
CWE-201Top Fix
Upgrade Version
Upgrade to version com.liferay:com.liferay.portal.security.audit.event.generators.user.management:5.0.13
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | HIGH |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | HIGH |
| Integrity (I): | NONE |
| Availability (A): | NONE |
Vulnerabilities
Projects
Contact Us


