CVE-2022-42344

EUVD-2022-6987
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Incorrect Authorization vulnerability. An authenticated attacker can exploit this vulnerability to achieve information exposure and privilege escalation.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
adobeCNA
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 37%
Affected Products (NVD)
VendorProductVersion
adobecommerce
𝑥
< 2.3.7
adobecommerce
2.4.0 ≤
𝑥
< 2.4.3
adobecommerce
2.3.7
adobecommerce
2.3.7:p1
adobecommerce
2.3.7:p2
adobecommerce
2.3.7:p3
adobecommerce
2.4.3
adobecommerce
2.4.3:p1
adobecommerce
2.4.3:p2
adobecommerce
2.4.4
magentomagento
𝑥
< 2.3.7
magentomagento
2.4.0 ≤
𝑥
< 2.4.3
magentomagento
2.3.7
magentomagento
2.3.7:p1
magentomagento
2.3.7:p2
magentomagento
2.3.7:p3
magentomagento
2.4.3
magentomagento
2.4.3:p1
magentomagento
2.4.3:p2
magentomagento
2.4.4
𝑥
= Vulnerable software versions