← Back

CVE-2025-43585

nvd nist
Published: Jun 10, 2025Modified: Jun 23, 2025

JSON object

Loading...
8.2
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
Exploitability: 3.9 / Impact: 4.2
Source: psirt@adobe.com (Secondary)

Description

Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access leading to a limited impact to confidentiality and a high impact to integrity. Exploitation of this issue does not require user interaction.

Affected (104)

3 products
Commerce
Commerce B2b
Magento
Configuration A
48 vulnerable
Vulnerable SoftwareAffected Versions
Adobe
Version 2.4.4
Version 2.4.4 p10
Version 2.4.4 p11
Version 2.4.4 p12
Version 2.4.4 p13
Version 2.4.4 p1
Version 2.4.4 p2
Version 2.4.4 p3
Version 2.4.4 p4
Version 2.4.4 p5
Version 2.4.4 p6
Version 2.4.4 p7
Version 2.4.4 p8
Version 2.4.4 p9
Version 2.4.5
Version 2.4.5 p10
Version 2.4.5 p11
Version 2.4.5 p12
Version 2.4.5 p1
Version 2.4.5 p2
Version 2.4.5 p3
Version 2.4.5 p4
Version 2.4.5 p5
Version 2.4.5 p6
Version 2.4.5 p7
Version 2.4.5 p8
Version 2.4.5 p9
Version 2.4.6
Version 2.4.6 p10
Version 2.4.6 p1
Version 2.4.6 p2
Version 2.4.6 p3
Version 2.4.6 p4
Version 2.4.6 p5
Version 2.4.6 p6
Version 2.4.6 p7
Version 2.4.6 p8
Version 2.4.6 p9
Version 2.4.7
Version 2.4.7 b1
Version 2.4.7 b2
Version 2.4.7 beta3
Version 2.4.7 p1
Version 2.4.7 p2
Version 2.4.7 p3
Version 2.4.7 p4
Version 2.4.7 p5
Version 2.4.8
Configuration B
22 vulnerable
Vulnerable SoftwareAffected Versions
Adobe
Version 1.3.3
Version 1.3.3 p10
Version 1.3.3 p11
Version 1.3.3 p12
Version 1.3.3 p13
Version 1.3.4
Version 1.3.4 p10
Version 1.3.4 p11
Version 1.3.4 p12
Version 1.3.4 p9
Version 1.3.5
Version 1.3.5 p10
Version 1.3.5 p7
Version 1.3.5 p8
Version 1.3.5 p9
Version 1.4.2
Version 1.4.2 p1
Version 1.4.2 p2
Version 1.4.2 p3
Version 1.4.2 p4
Version 1.4.2 p5
Version 1.5.2
Configuration C
34 vulnerable
Vulnerable SoftwareAffected Versions
Adobe
Version 2.4.5
Version 2.4.5 p10
Version 2.4.5 p11
Version 2.4.5 p12
Version 2.4.5 p1
Version 2.4.5 p2
Version 2.4.5 p3
Version 2.4.5 p4
Version 2.4.5 p5
Version 2.4.5 p6
Version 2.4.5 p7
Version 2.4.5 p8
Version 2.4.5 p9
Version 2.4.6
Version 2.4.6 p10
Version 2.4.6 p1
Version 2.4.6 p2
Version 2.4.6 p3
Version 2.4.6 p4
Version 2.4.6 p5
Version 2.4.6 p6
Version 2.4.6 p7
Version 2.4.6 p8
Version 2.4.6 p9
Version 2.4.7
Version 2.4.7 b1
Version 2.4.7 b2
Version 2.4.7 beta3
Version 2.4.7 p1
Version 2.4.7 p2
Version 2.4.7 p3
Version 2.4.7 p4
Version 2.4.7 p5
Version 2.4.8

References (1)

Timeline

No history available yet.