4.3

CVE-2025-24419

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could exploit this vulnerability to modify select data. Exploitation of this issue does not require user interaction.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AdobeCommerce B2b Version < 1.3.3
AdobeCommerce B2b Version1.3.3 Update-
AdobeCommerce B2b Version1.3.3 Updatep10
AdobeCommerce B2b Version1.3.3 Updatep11
AdobeCommerce B2b Version1.3.4 Update-
AdobeCommerce B2b Version1.3.4 Updatep10
AdobeCommerce B2b Version1.3.4 Updatep9
AdobeCommerce B2b Version1.3.5 Update-
AdobeCommerce B2b Version1.3.5 Updatep7
AdobeCommerce B2b Version1.3.5 Updatep8
AdobeCommerce B2b Version1.4.2 Update-
AdobeCommerce B2b Version1.4.2 Updatep1
AdobeCommerce B2b Version1.4.2 Updatep2
AdobeCommerce B2b Version1.4.2 Updatep3
AdobeCommerce B2b Version1.5.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.08% 0.247
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
psirt@adobe.com 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.