CVE-2023-22251

EUVD-2023-26415
Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an Incorrect Authorization vulnerability. A low-privileged authenticated attacker could leverage this vulnerability to achieve minor information disclosure.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
adobeCNA
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 52%
Affected Products (NVD)
VendorProductVersion
adobecommerce
𝑥
< 2.4.4
adobecommerce
2.4.4
adobecommerce
2.4.4:p1
adobecommerce
2.4.4:p2
adobecommerce
2.4.5
adobecommerce
2.4.5:p1
adobemagento_open_source
𝑥
< 2.4.4
adobemagento_open_source
2.4.4
adobemagento_open_source
2.4.4:p1
adobemagento_open_source
2.4.4:p2
adobemagento_open_source
2.4.5
adobemagento_open_source
2.4.5:p1
𝑥
= Vulnerable software versions