CVE-2023-22248

EUVD-2023-26412
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. An attacker could leverage this vulnerability to leak another user's data. Exploitation of this issue does not require user interaction.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
adobeCNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 34%
Affected Products (NVD)
VendorProductVersion
adobecommerce
2.3.7
adobecommerce
2.3.7:p1
adobecommerce
2.3.7:p2
adobecommerce
2.3.7:p3
adobecommerce
2.3.7:p4
adobecommerce
2.3.7:p4-ext1
adobecommerce
2.3.7:p4-ext2
adobecommerce
2.4.0
adobecommerce
2.4.0:ext-1
adobecommerce
2.4.0:ext-2
adobecommerce
2.4.1
adobecommerce
2.4.1:ext-1
adobecommerce
2.4.1:ext-2
adobecommerce
2.4.2
adobecommerce
2.4.2:ext-1
adobecommerce
2.4.2:ext-2
adobecommerce
2.4.3
adobecommerce
2.4.3:ext-1
adobecommerce
2.4.3:ext-2
adobecommerce
2.4.4
adobecommerce
2.4.4:p1
adobecommerce
2.4.4:p2
adobecommerce
2.4.4:p3
adobecommerce
2.4.5
adobecommerce
2.4.5:p1
adobecommerce
2.4.5:p2
adobecommerce
2.4.6
adobemagento
2.4.4
adobemagento
2.4.4:p1
adobemagento
2.4.4:p2
adobemagento
2.4.4:p3
adobemagento
2.4.5
adobemagento
2.4.5:p1
adobemagento
2.4.5:p2
adobemagento
2.4.6
𝑥
= Vulnerable software versions