Liferay 7.4.x & DXP 2024.Q1.x Password Enumeration via Brute Force CVE-2025-62257
CVE-2025-62257 Published on October 29, 2025
Password enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allows remote attackers to determine a users password even if account lockout is enabled via brute force attack.
Weakness Type
Improper Restriction of Excessive Authentication Attempts
The software does not implement sufficient measures to prevent multiple failed authentication attempts within in a short time frame, making it more susceptible to brute force attacks.
Products Associated with CVE-2025-62257
stack.watch emails you whenever new vulnerabilities are published in Liferay Portal or Liferay Digital Experience Platform. Just hit a watch button to start following.
Affected Versions
Liferay Portal:- Version 7.4.0, <= 7.4.3.119 is affected.
- Version 7.4.13, <= 7.4.13-u92 is affected.
- Version 2023.Q3.1, <= 2023.Q3.10 is affected.
- Version 2023.Q4.0, <= 2023.Q4.10 is affected.
- Version 2024.Q1.1, <= 2024.Q1.5 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.