Adobe Commerce Vulnerable to Improper Authentication Attacks
CVE-2024-45148

8.8HIGH

Key Information:

Vendor
Adobe
Vendor
CVE Published:
10 October 2024

Summary

An improper authentication vulnerability exists in Adobe Commerce affecting several versions, potentially allowing low-privileged attackers to bypass security mechanisms and gain unauthorized access to sensitive data and system functionalities. This vulnerability can be exploited without user interaction, making it easier for malevolent actors to leverage it for nefarious purposes. Organizations using the affected versions are urged to review their security measures and apply necessary patches to mitigate risks associated with this vulnerability.

Affected Version(s)

Adobe Commerce 0 <= 2.4.4-p10

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.