← back
CVE-2025-62247

CVE-2025-62247

CVSS 2 LOWEPSS 0.2%CWE-862
Vexday Risk Score
8Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 2EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
22 Oct 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Missing Authorization in Collection Provider component in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 through 2025.Q1.16, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.19 allows instance users to read and select unauthorized Blueprints through the Collection Providers across instances.
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →