CVE Vulnerabilities

CVE-2022-35689

Published: Oct 14, 2022 | Modified: Oct 19, 2022
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the availability of a users minor feature. Exploitation of this issue does not require user interaction.

Affected Software

Name Vendor Start Version End Version
Commerce Adobe * 2.4.4 (excluding)
Commerce Adobe 2.4.4 (including) 2.4.4 (including)
Commerce Adobe 2.4.4-p1 (including) 2.4.4-p1 (including)
Commerce Adobe 2.4.5 (including) 2.4.5 (including)
Magento_open_source Adobe * 2.4.4 (excluding)
Magento_open_source Adobe 2.4.4 (including) 2.4.4 (including)
Magento_open_source Adobe 2.4.4-p1 (including) 2.4.4-p1 (including)
Magento_open_source Adobe 2.4.5 (including) 2.4.5 (including)

References