Liferay Portal and DXP Insecure Direct Object Reference Vulnerability in Audit Events

Vulnerability

An Insecure Direct Object Reference (IDOR) vulnerability has been identified in Liferay Portal versions 7.4.0 through 7.4.3.117, as well as in several Liferay DXP versions. This vulnerability allows remote authenticated users to access audit events from different virtual instances by manipulating the '_com_liferay_portal_security_audit_web_portlet_AuditPortlet_auditEventId' parameter.

Impact

Exploitation of this vulnerability allows for unauthorized access to audit events from different virtual instances, potentially leading to information disclosure.

Remediation

Users can upgrade to Liferay Portal 7.4.3.118 or Liferay DXP 2024.Q1.6 or 2024.Q2.0 to address this vulnerability.

Added: Sep 30, 2025, 7:17 PM
Updated: Sep 30, 2025, 7:17 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
0.6
exploitability
4.8
remediation
7.7
relevance
0.6
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.