CVE-2025-3594
Last modified
CVE-2025-3594 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. Path traversal vulnerability with the downloading and installation of Xuggler in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through update 34, and older unsupported versions allows remote attackers to (1) add files to arbitrary locations on the server and (2) download and execute arbitrary files from the download server via the `_com_liferay_server_admin_web_portlet_ServerAdminPortlet_jarName` parameter.. EPSS estimates a 0.58% chance of exploitation in the next 30 days.
Description
Path traversal vulnerability with the downloading and installation of Xuggler in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through update 34, and older unsupported versions allows remote attackers to (1) add files to arbitrary locations on the server and (2) download and execute arbitrary files from the download server via the `_com_liferay_server_admin_web_portlet_ServerAdminPortlet_jarName` parameter.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Liferay | Digital Experience Platform | >= 7.0, <= 7.2 | — |
| Liferay | Digital Experience Platform | 7.3 | — |
| Liferay | Digital Experience Platform | 7.4 | Update1 |
| Liferay | Liferay Portal | >= 7.0.0, <= 7.4.3.4 | — |
| Liferay | Liferay Portal | 6.2 | — |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-3594?
How severe is CVE-2025-3594?
How do I fix CVE-2025-3594?
Are you affected by CVE-2025-3594?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
