← Back

CVE-2025-27192

nvd nist
Published: Apr 8, 2025Modified: May 20, 2025

JSON object

Loading...
2.7
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Exploitability: 1.2 / Impact: 1.4
Source: psirt@adobe.com (Secondary)

Description

Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Insufficiently Protected Credentials vulnerability that could lead to a security feature bypass. A high privileged attacker could exploit this vulnerability to gain unauthorized access to protected resources by obtaining sensitive credential information. Exploitation of this issue does not require user interaction.

Affected (109)

3 products
Commerce
Commerce B2b
Magento
Configuration A
45 vulnerable
Vulnerable SoftwareAffected Versions
Adobe
Before 2.4.4
Version 2.4.4
Version 2.4.4 p10
Version 2.4.4 p11
Version 2.4.4 p12
Version 2.4.4 p1
Version 2.4.4 p2
Version 2.4.4 p3
Version 2.4.4 p4
Version 2.4.4 p5
Version 2.4.4 p6
Version 2.4.4 p7
Version 2.4.4 p8
Version 2.4.4 p9
Version 2.4.5
Version 2.4.5 p10
Version 2.4.5 p11
Version 2.4.5 p1
Version 2.4.5 p2
Version 2.4.5 p3
Version 2.4.5 p4
Version 2.4.5 p5
Version 2.4.5 p6
Version 2.4.5 p7
Version 2.4.5 p8
Version 2.4.5 p9
Version 2.4.6
Version 2.4.6 p1
Version 2.4.6 p2
Version 2.4.6 p3
Version 2.4.6 p4
Version 2.4.6 p5
Version 2.4.6 p6
Version 2.4.6 p7
Version 2.4.6 p8
Version 2.4.6 p9
Version 2.4.7
Version 2.4.7 b1
Version 2.4.7 b2
Version 2.4.7 beta3
Version 2.4.7 p1
Version 2.4.7 p2
Version 2.4.7 p3
Version 2.4.7 p4
Version 2.4.8 beta2
Configuration B
19 vulnerable
Vulnerable SoftwareAffected Versions
Adobe
Before 1.3.3
Version 1.3.3
Version 1.3.3 p10
Version 1.3.3 p11
Version 1.3.3 p12
Version 1.3.4
Version 1.3.4 p10
Version 1.3.4 p11
Version 1.3.4 p9
Version 1.3.5
Version 1.3.5 p7
Version 1.3.5 p8
Version 1.3.5 p9
Version 1.4.2
Version 1.4.2 p1
Version 1.4.2 p2
Version 1.4.2 p3
Version 1.4.2 p4
Version 1.5.1
Configuration C
45 vulnerable
Vulnerable SoftwareAffected Versions
Adobe
Before 2.4.4
Version 2.4.4
Version 2.4.4 p10
Version 2.4.4 p11
Version 2.4.4 p12
Version 2.4.4 p1
Version 2.4.4 p2
Version 2.4.4 p3
Version 2.4.4 p4
Version 2.4.4 p5
Version 2.4.4 p6
Version 2.4.4 p7
Version 2.4.4 p8
Version 2.4.4 p9
Version 2.4.5
Version 2.4.5 p10
Version 2.4.5 p11
Version 2.4.5 p1
Version 2.4.5 p2
Version 2.4.5 p3
Version 2.4.5 p4
Version 2.4.5 p5
Version 2.4.5 p6
Version 2.4.5 p7
Version 2.4.5 p8
Version 2.4.5 p9
Version 2.4.6
Version 2.4.6 p1
Version 2.4.6 p2
Version 2.4.6 p3
Version 2.4.6 p4
Version 2.4.6 p5
Version 2.4.6 p6
Version 2.4.6 p7
Version 2.4.6 p8
Version 2.4.6 p9
Version 2.4.7
Version 2.4.7 b1
Version 2.4.7 b2
Version 2.4.7 beta3
Version 2.4.7 p1
Version 2.4.7 p2
Version 2.4.7 p3
Version 2.4.7 p4
Version 2.4.8 beta2

References (1)

Source: psirt@adobe.com
PatchVendor Advisory

Timeline

No history available yet.