SessionClicks in Liferay Portal 7.0.0 through 7.4.3.21, and Liferay DXP...
Vulnerability Description
SessionClicks in Liferay Portal 7.0.0 through 7.4.3.21, and Liferay DXP 7.4 GA through update 9, 7.3 GA through update 25, and older unsupported versions does not restrict the saving of request parameters in the HTTP session, which allows remote attackers to consume system memory leading to denial-of-service (DoS) conditions via crafted HTTP requests.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-3526
Credits & Attribution
No credits recorded in the NVD database.
More from Liferay
View All →Affected Vendor
Liferay
View all reports →