CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
72.8%
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to access other user’s data. Exploitation of this issue does not require user interaction.
github.com/magento/magento2
github.com/magento/magento2/commit/246d524b7586af2245092008e0d92b8d6fdd8523
github.com/magento/magento2/commit/5548bc64b5bc904346c0af9193a7fbb5274b4efa
github.com/magento/magento2/commit/5f07eba878296a37bd5c3a2baecad48948547594
helpx.adobe.com/security/products/magento/apsb22-38.html
nvd.nist.gov/vuln/detail/CVE-2022-34256
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
72.8%