# CVE-2025-43801

## Summary

- **CVE ID:** CVE-2025-43801
- **Severity:** MEDIUM
- **CVSS Score:** 6.9 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N)
- **CWE:** CWE-606
- **Published:** Sep 16, 2025
- **Last Modified:** Mar 13, 2026

## Description

Unchecked input for loop condition vulnerability in XML-RPC in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to perform a denial-of-service (DoS) attacks via a crafted XML-RPC request.

## Affected Products

- Liferay — Portal (7.4.0)
- Liferay — DXP (7.3.10)
- Liferay — DXP (7.4.13)
- Liferay — DXP (2023.Q3.1)
- Liferay — DXP (2023.Q4.0)

## References

- [CNA](https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2025-43801)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.40%
- **EPSS Percentile:** 33.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._