CVE Vulnerabilities

CVE-2022-35692

Published: Aug 19, 2022 | Modified: Jun 29, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to leak minor information of another users account detials. Exploitation of this issue does not require user interaction.

Affected Software

Name Vendor Start Version End Version
Commerce Adobe 2.4.0 (including) 2.4.4 (excluding)
Magento_commerce Adobe 2.3.7 (including) 2.3.7 (including)
Magento_commerce Adobe 2.3.7-p1 (including) 2.3.7-p1 (including)
Magento_commerce Adobe 2.3.7-p2 (including) 2.3.7-p2 (including)
Magento_commerce Adobe 2.3.7-p3 (including) 2.3.7-p3 (including)
Magento_commerce Adobe 2.4.3 (including) 2.4.3 (including)
Magento_commerce Adobe 2.4.3-p1 (including) 2.4.3-p1 (including)
Magento_commerce Adobe 2.4.3-p2 (including) 2.4.3-p2 (including)
Magento_commerce Adobe 2.4.4 (including) 2.4.4 (including)

References