CVE-2022-34256
Adobe Commerce Improper Authorization Privilege escalation
Severity Score
9.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to access other user's data. Exploitation of this issue does not require user interaction.
Adobe Commerce versiones 2.4.3-p2 (y anteriores), 2.3.7-p3 (y anteriores) y 2.4.4 (y anteriores) están afectadas por una vulnerabilidad de Autorización Inapropiada que podría resultar en una escalada de Privilegios. Un atacante podría aprovechar esta vulnerabilidad para acceder a los datos de otros usuarios. No es requerida una interacción del usuario para la explotación de este problema.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2022-06-21 CVE Reserved
- 2022-08-16 CVE Published
- 2024-09-17 CVE Updated
- 2024-09-25 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-285: Improper Authorization
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://helpx.adobe.com/security/products/magento/apsb22-38.html | 2022-08-31 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | >= 2.3.0 < 2.3.7 Search vendor "Adobe" for product "Commerce" and version " >= 2.3.0 < 2.3.7" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | >= 2.4.0 < 2.4.3 Search vendor "Adobe" for product "Commerce" and version " >= 2.4.0 < 2.4.3" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.3.7 Search vendor "Adobe" for product "Commerce" and version "2.3.7" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.3.7 Search vendor "Adobe" for product "Commerce" and version "2.3.7" | p1 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.3.7 Search vendor "Adobe" for product "Commerce" and version "2.3.7" | p2 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.3.7 Search vendor "Adobe" for product "Commerce" and version "2.3.7" | p3 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.4.3 Search vendor "Adobe" for product "Commerce" and version "2.4.3" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.4.3 Search vendor "Adobe" for product "Commerce" and version "2.4.3" | p1 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.4.3 Search vendor "Adobe" for product "Commerce" and version "2.4.3" | p2 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Commerce Search vendor "Adobe" for product "Commerce" | 2.4.4 Search vendor "Adobe" for product "Commerce" and version "2.4.4" | - |
Affected
| ||||||
Magento Search vendor "Magento" | Magento Search vendor "Magento" for product "Magento" | >= 2.3.0 < 2.3.7 Search vendor "Magento" for product "Magento" and version " >= 2.3.0 < 2.3.7" | commerce |
Affected
| ||||||
Magento Search vendor "Magento" | Magento Search vendor "Magento" for product "Magento" | >= 2.4.0 < 2.4.3 Search vendor "Magento" for product "Magento" and version " >= 2.4.0 < 2.4.3" | commerce |
Affected
| ||||||
Magento Search vendor "Magento" | Magento Search vendor "Magento" for product "Magento" | 2.3.7 Search vendor "Magento" for product "Magento" and version "2.3.7" | commerce |
Affected
| ||||||
Magento Search vendor "Magento" | Magento Search vendor "Magento" for product "Magento" | 2.3.7 Search vendor "Magento" for product "Magento" and version "2.3.7" | p1, commerce |
Affected
| ||||||
Magento Search vendor "Magento" | Magento Search vendor "Magento" for product "Magento" | 2.3.7 Search vendor "Magento" for product "Magento" and version "2.3.7" | p2, commerce |
Affected
| ||||||
Magento Search vendor "Magento" | Magento Search vendor "Magento" for product "Magento" | 2.3.7 Search vendor "Magento" for product "Magento" and version "2.3.7" | p3, commerce |
Affected
| ||||||
Magento Search vendor "Magento" | Magento Search vendor "Magento" for product "Magento" | 2.4.3 Search vendor "Magento" for product "Magento" and version "2.4.3" | commerce |
Affected
| ||||||
Magento Search vendor "Magento" | Magento Search vendor "Magento" for product "Magento" | 2.4.3 Search vendor "Magento" for product "Magento" and version "2.4.3" | p1, commerce |
Affected
| ||||||
Magento Search vendor "Magento" | Magento Search vendor "Magento" for product "Magento" | 2.4.3 Search vendor "Magento" for product "Magento" and version "2.4.3" | p2, commerce |
Affected
| ||||||
Magento Search vendor "Magento" | Magento Search vendor "Magento" for product "Magento" | 2.4.4 Search vendor "Magento" for product "Magento" and version "2.4.4" | commerce |
Affected
|