2.7

CVE-2025-27192

Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Insufficiently Protected Credentials vulnerability that could lead to a security feature bypass. A high privileged attacker could exploit this vulnerability to gain unauthorized access to protected resources by obtaining sensitive credential information. Exploitation of this issue does not require user interaction.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Data is provided by the National Vulnerability Database (NVD)
AdobeCommerce Version < 2.4.4
AdobeCommerce Version2.4.4 Update-
AdobeCommerce Version2.4.4 Updatep1
AdobeCommerce Version2.4.4 Updatep10
AdobeCommerce Version2.4.4 Updatep11
AdobeCommerce Version2.4.4 Updatep12
AdobeCommerce Version2.4.4 Updatep2
AdobeCommerce Version2.4.4 Updatep3
AdobeCommerce Version2.4.4 Updatep4
AdobeCommerce Version2.4.4 Updatep5
AdobeCommerce Version2.4.4 Updatep6
AdobeCommerce Version2.4.4 Updatep7
AdobeCommerce Version2.4.4 Updatep8
AdobeCommerce Version2.4.4 Updatep9
AdobeCommerce Version2.4.5 Update-
AdobeCommerce Version2.4.5 Updatep1
AdobeCommerce Version2.4.5 Updatep10
AdobeCommerce Version2.4.5 Updatep11
AdobeCommerce Version2.4.5 Updatep2
AdobeCommerce Version2.4.5 Updatep3
AdobeCommerce Version2.4.5 Updatep4
AdobeCommerce Version2.4.5 Updatep5
AdobeCommerce Version2.4.5 Updatep6
AdobeCommerce Version2.4.5 Updatep7
AdobeCommerce Version2.4.5 Updatep8
AdobeCommerce Version2.4.5 Updatep9
AdobeCommerce Version2.4.6 Update-
AdobeCommerce Version2.4.6 Updatep1
AdobeCommerce Version2.4.6 Updatep2
AdobeCommerce Version2.4.6 Updatep3
AdobeCommerce Version2.4.6 Updatep4
AdobeCommerce Version2.4.6 Updatep5
AdobeCommerce Version2.4.6 Updatep6
AdobeCommerce Version2.4.6 Updatep7
AdobeCommerce Version2.4.6 Updatep8
AdobeCommerce Version2.4.6 Updatep9
AdobeCommerce Version2.4.7 Update-
AdobeCommerce Version2.4.7 Updateb1
AdobeCommerce Version2.4.7 Updateb2
AdobeCommerce Version2.4.7 Updatebeta3
AdobeCommerce Version2.4.7 Updatep1
AdobeCommerce Version2.4.7 Updatep2
AdobeCommerce Version2.4.7 Updatep3
AdobeCommerce Version2.4.7 Updatep4
AdobeCommerce Version2.4.8 Updatebeta2
AdobeCommerce B2b Version < 1.3.3
AdobeCommerce B2b Version1.3.3 Update-
AdobeCommerce B2b Version1.3.3 Updatep10
AdobeCommerce B2b Version1.3.3 Updatep11
AdobeCommerce B2b Version1.3.3 Updatep12
AdobeCommerce B2b Version1.3.4 Update-
AdobeCommerce B2b Version1.3.4 Updatep10
AdobeCommerce B2b Version1.3.4 Updatep11
AdobeCommerce B2b Version1.3.4 Updatep9
AdobeCommerce B2b Version1.3.5 Update-
AdobeCommerce B2b Version1.3.5 Updatep7
AdobeCommerce B2b Version1.3.5 Updatep8
AdobeCommerce B2b Version1.3.5 Updatep9
AdobeCommerce B2b Version1.4.2 Update-
AdobeCommerce B2b Version1.4.2 Updatep1
AdobeCommerce B2b Version1.4.2 Updatep2
AdobeCommerce B2b Version1.4.2 Updatep3
AdobeCommerce B2b Version1.4.2 Updatep4
AdobeCommerce B2b Version1.5.1 Update-
AdobeMagento Version < 2.4.4
AdobeMagento Version2.4.4 Update- SwEditionopen_source
AdobeMagento Version2.4.4 Updatep1 SwEditionopen_source
AdobeMagento Version2.4.4 Updatep10 SwEditionopen_source
AdobeMagento Version2.4.4 Updatep11 SwEditionopen_source
AdobeMagento Version2.4.4 Updatep12 SwEditionopen_source
AdobeMagento Version2.4.4 Updatep2 SwEditionopen_source
AdobeMagento Version2.4.4 Updatep3 SwEditionopen_source
AdobeMagento Version2.4.4 Updatep4 SwEditionopen_source
AdobeMagento Version2.4.4 Updatep5 SwEditionopen_source
AdobeMagento Version2.4.4 Updatep6 SwEditionopen_source
AdobeMagento Version2.4.4 Updatep7 SwEditionopen_source
AdobeMagento Version2.4.4 Updatep8 SwEditionopen_source
AdobeMagento Version2.4.4 Updatep9 SwEditionopen_source
AdobeMagento Version2.4.5 Update- SwEditionopen_source
AdobeMagento Version2.4.5 Updatep1 SwEditionopen_source
AdobeMagento Version2.4.5 Updatep10 SwEditionopen_source
AdobeMagento Version2.4.5 Updatep11 SwEditionopen_source
AdobeMagento Version2.4.5 Updatep2 SwEditionopen_source
AdobeMagento Version2.4.5 Updatep3 SwEditionopen_source
AdobeMagento Version2.4.5 Updatep4 SwEditionopen_source
AdobeMagento Version2.4.5 Updatep5 SwEditionopen_source
AdobeMagento Version2.4.5 Updatep6 SwEditionopen_source
AdobeMagento Version2.4.5 Updatep7 SwEditionopen_source
AdobeMagento Version2.4.5 Updatep8 SwEditionopen_source
AdobeMagento Version2.4.5 Updatep9 SwEditionopen_source
AdobeMagento Version2.4.6 Update- SwEditionopen_source
AdobeMagento Version2.4.6 Updatep1 SwEditionopen_source
AdobeMagento Version2.4.6 Updatep2 SwEditionopen_source
AdobeMagento Version2.4.6 Updatep3 SwEditionopen_source
AdobeMagento Version2.4.6 Updatep4 SwEditionopen_source
AdobeMagento Version2.4.6 Updatep5 SwEditionopen_source
AdobeMagento Version2.4.6 Updatep6 SwEditionopen_source
AdobeMagento Version2.4.6 Updatep7 SwEditionopen_source
AdobeMagento Version2.4.6 Updatep8 SwEditionopen_source
AdobeMagento Version2.4.6 Updatep9 SwEditionopen_source
AdobeMagento Version2.4.7 Update- SwEditionopen_source
AdobeMagento Version2.4.7 Updateb1 SwEditionopen_source
AdobeMagento Version2.4.7 Updateb2 SwEditionopen_source
AdobeMagento Version2.4.7 Updatebeta3 SwEditionopen_source
AdobeMagento Version2.4.7 Updatep1 SwEditionopen_source
AdobeMagento Version2.4.7 Updatep2 SwEditionopen_source
AdobeMagento Version2.4.7 Updatep3 SwEditionopen_source
AdobeMagento Version2.4.7 Updatep4 SwEditionopen_source
AdobeMagento Version2.4.8 Updatebeta2 SwEditionopen_source
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.08% 0.248
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
psirt@adobe.com 2.7 1.2 1.4
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
CWE-522 Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.