CVE Vulnerabilities

CVE-2025-62261

Cleartext Storage of Sensitive Information

Published: Oct 27, 2025 | Modified: Nov 10, 2025
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Liferay Portal 7.4.0 through 7.4.3.99, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 34, and older unsupported versions stores password reset tokens in plain text, which allows attackers with access to the database to obtain the token, reset a user’s password and take over the user’s account.

Weakness

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Affected Software

Name Vendor Start Version End Version
Digital_experience_platform Liferay 7.3 (including) 7.3 (including)
Digital_experience_platform Liferay 7.3-fix_pack_1 (including) 7.3-fix_pack_1 (including)
Digital_experience_platform Liferay 7.3-fix_pack_2 (including) 7.3-fix_pack_2 (including)
Digital_experience_platform Liferay 7.3-service_pack_1 (including) 7.3-service_pack_1 (including)
Digital_experience_platform Liferay 7.3-service_pack_2 (including) 7.3-service_pack_2 (including)
Digital_experience_platform Liferay 7.3-service_pack_3 (including) 7.3-service_pack_3 (including)
Digital_experience_platform Liferay 7.3-update1 (including) 7.3-update1 (including)
Digital_experience_platform Liferay 7.3-update10 (including) 7.3-update10 (including)
Digital_experience_platform Liferay 7.3-update11 (including) 7.3-update11 (including)
Digital_experience_platform Liferay 7.3-update12 (including) 7.3-update12 (including)
Digital_experience_platform Liferay 7.3-update13 (including) 7.3-update13 (including)
Digital_experience_platform Liferay 7.3-update14 (including) 7.3-update14 (including)
Digital_experience_platform Liferay 7.3-update15 (including) 7.3-update15 (including)
Digital_experience_platform Liferay 7.3-update16 (including) 7.3-update16 (including)
Digital_experience_platform Liferay 7.3-update17 (including) 7.3-update17 (including)
Digital_experience_platform Liferay 7.3-update18 (including) 7.3-update18 (including)
Digital_experience_platform Liferay 7.3-update19 (including) 7.3-update19 (including)
Digital_experience_platform Liferay 7.3-update2 (including) 7.3-update2 (including)
Digital_experience_platform Liferay 7.3-update20 (including) 7.3-update20 (including)
Digital_experience_platform Liferay 7.3-update21 (including) 7.3-update21 (including)
Digital_experience_platform Liferay 7.3-update22 (including) 7.3-update22 (including)
Digital_experience_platform Liferay 7.3-update23 (including) 7.3-update23 (including)
Digital_experience_platform Liferay 7.3-update24 (including) 7.3-update24 (including)
Digital_experience_platform Liferay 7.3-update25 (including) 7.3-update25 (including)
Digital_experience_platform Liferay 7.3-update26 (including) 7.3-update26 (including)
Digital_experience_platform Liferay 7.3-update27 (including) 7.3-update27 (including)
Digital_experience_platform Liferay 7.3-update28 (including) 7.3-update28 (including)
Digital_experience_platform Liferay 7.3-update29 (including) 7.3-update29 (including)
Digital_experience_platform Liferay 7.3-update3 (including) 7.3-update3 (including)
Digital_experience_platform Liferay 7.3-update30 (including) 7.3-update30 (including)
Digital_experience_platform Liferay 7.3-update31 (including) 7.3-update31 (including)
Digital_experience_platform Liferay 7.3-update32 (including) 7.3-update32 (including)
Digital_experience_platform Liferay 7.3-update33 (including) 7.3-update33 (including)
Digital_experience_platform Liferay 7.3-update34 (including) 7.3-update34 (including)
Digital_experience_platform Liferay 7.3-update4 (including) 7.3-update4 (including)
Digital_experience_platform Liferay 7.3-update5 (including) 7.3-update5 (including)
Digital_experience_platform Liferay 7.3-update6 (including) 7.3-update6 (including)
Digital_experience_platform Liferay 7.3-update7 (including) 7.3-update7 (including)
Digital_experience_platform Liferay 7.3-update8 (including) 7.3-update8 (including)
Digital_experience_platform Liferay 7.3-update9 (including) 7.3-update9 (including)
Digital_experience_platform Liferay 7.4 (including) 7.4 (including)
Digital_experience_platform Liferay 2023.q3.1 (including) 2023.q3.1 (including)
Digital_experience_platform Liferay 2023.q3.2 (including) 2023.q3.2 (including)
Digital_experience_platform Liferay 2023.q3.3 (including) 2023.q3.3 (including)
Digital_experience_platform Liferay 2023.q3.4 (including) 2023.q3.4 (including)
Liferay_portal Liferay 7.0.0 (including) 7.4.3.100 (excluding)

Potential Mitigations

References