CVE Vulnerabilities

CVE-2022-34256

Published: Aug 16, 2022 | Modified: Aug 31, 2022
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to access other users data. Exploitation of this issue does not require user interaction.

Affected Software

Name Vendor Start Version End Version
Commerce Adobe 2.3.0 (including) 2.3.7 (excluding)
Commerce Adobe 2.4.0 (including) 2.4.3 (excluding)
Commerce Adobe 2.3.7 (including) 2.3.7 (including)
Commerce Adobe 2.3.7-p1 (including) 2.3.7-p1 (including)
Commerce Adobe 2.3.7-p2 (including) 2.3.7-p2 (including)
Commerce Adobe 2.3.7-p3 (including) 2.3.7-p3 (including)
Commerce Adobe 2.4.3 (including) 2.4.3 (including)
Commerce Adobe 2.4.3-p1 (including) 2.4.3-p1 (including)
Commerce Adobe 2.4.3-p2 (including) 2.4.3-p2 (including)
Commerce Adobe 2.4.4 (including) 2.4.4 (including)
Magento Magento 2.3.0 (including) 2.3.7 (excluding)
Magento Magento 2.4.0 (including) 2.4.3 (excluding)
Magento Magento 2.3.7 (including) 2.3.7 (including)
Magento Magento 2.3.7-p1 (including) 2.3.7-p1 (including)
Magento Magento 2.3.7-p2 (including) 2.3.7-p2 (including)
Magento Magento 2.3.7-p3 (including) 2.3.7-p3 (including)
Magento Magento 2.4.3 (including) 2.4.3 (including)
Magento Magento 2.4.3-p1 (including) 2.4.3-p1 (including)
Magento Magento 2.4.3-p2 (including) 2.4.3-p2 (including)
Magento Magento 2.4.4 (including) 2.4.4 (including)

References