Liferay Portal and DXP Path Traversal Vulnerability in ComboServlet Allowing Denial-of-Service

Vulnerability

A path traversal vulnerability leading to denial-of-service has been identified in the ComboServlet of Liferay Portal versions 7.4.0 to 7.4.3.107, as well as in several Liferay DXP versions. This vulnerability allows remote attackers to access arbitrary CSS and JSS files, loading them multiple times through the query string of a URL.

Impact

Exploitation of this vulnerability could lead to a denial-of-service condition, causing the application to become unresponsive or unavailable.

Remediation

Users can upgrade to Liferay Portal 7.4.3.108 or Liferay DXP versions 2024.Q1.1, 2023.Q4.5, 2023.Q3.9, or 7.3 U36.

Added: Sep 29, 2025, 11:22 PM
Updated: Sep 29, 2025, 11:22 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
3.8
exploitability
8.1
remediation
7.7
relevance
0.6
threat
0.0
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.