← Back

CVE-2025-49559

nvd nist
Published: Aug 12, 2025Modified: Aug 15, 2025

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Exploitability: 3.9 / Impact: 1.4
Source: psirt@adobe.com (Secondary)

Description

Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a security feature bypass. An attacker could leverage this vulnerability to modify limited data. Exploitation of this issue does not require user interaction.

Affected (148)

3 products
Commerce
Magento
Commerce B2b
Configuration A
54 vulnerable
Vulnerable SoftwareAffected Versions
Adobe
Before 2.4.4
Version 2.4.4
Version 2.4.4 p10
Version 2.4.4 p11
Version 2.4.4 p12
Version 2.4.4 p13
Version 2.4.4 p14
Version 2.4.4 p1
Version 2.4.4 p2
Version 2.4.4 p3
Version 2.4.4 p4
Version 2.4.4 p5
Version 2.4.4 p6
Version 2.4.4 p7
Version 2.4.4 p8
Version 2.4.4 p9
Version 2.4.5
Version 2.4.5 p10
Version 2.4.5 p11
Version 2.4.5 p12
Version 2.4.5 p13
Version 2.4.5 p1
Version 2.4.5 p2
Version 2.4.5 p3
Version 2.4.5 p4
Version 2.4.5 p5
Version 2.4.5 p6
Version 2.4.5 p7
Version 2.4.5 p8
Version 2.4.5 p9
Version 2.4.6
Version 2.4.6 p10
Version 2.4.6 p11
Version 2.4.6 p1
Version 2.4.6 p2
Version 2.4.6 p3
Version 2.4.6 p4
Version 2.4.6 p5
Version 2.4.6 p6
Version 2.4.6 p7
Version 2.4.6 p8
Version 2.4.6 p9
Version 2.4.7
Version 2.4.7 b1
Version 2.4.7 b2
Version 2.4.7 beta3
Version 2.4.7 p1
Version 2.4.7 p2
Version 2.4.7 p3
Version 2.4.7 p4
Version 2.4.7 p5
Version 2.4.7 p6
Version 2.4.8
Version 2.4.8 beta1
Configuration B
42 vulnerable
Vulnerable SoftwareAffected Versions
Adobe
Before 2.4.5
Version 2.4.5
Version 2.4.5 p10
Version 2.4.5 p11
Version 2.4.5 p12
Version 2.4.5 p13
Version 2.4.5 p1
Version 2.4.5 p2
Version 2.4.5 p3
Version 2.4.5 p4
Version 2.4.5 p5
Version 2.4.5 p6
Version 2.4.5 p7
Version 2.4.5 p8
Version 2.4.5 p9
Version 2.4.6
Version 2.4.6 p10
Version 2.4.6 p11
Version 2.4.6 p1
Version 2.4.6 p2
Version 2.4.6 p3
Version 2.4.6 p4
Version 2.4.6 p5
Version 2.4.6 p6
Version 2.4.6 p7
Version 2.4.6 p8
Version 2.4.6 p9
Version 2.4.7
Version 2.4.7 b1
Version 2.4.7 b2
Version 2.4.7 beta3
Version 2.4.7 p1
Version 2.4.7 p2
Version 2.4.7 p3
Version 2.4.7 p4
Version 2.4.7 p5
Version 2.4.7 p6
Version 2.4.8
Version 2.4.8 beta1
Version 2.4.8 beta2
Version 2.4.8 p1
Version 2.4.9 alpha1
Configuration C
52 vulnerable
Vulnerable SoftwareAffected Versions
Adobe
Before 1.3.3
Version 1.3.3
Version 1.3.3 p10
Version 1.3.3 p11
Version 1.3.3 p12
Version 1.3.3 p13
Version 1.3.3 p14
Version 1.3.3 p1
Version 1.3.3 p2
Version 1.3.3 p3
Version 1.3.3 p4
Version 1.3.3 p5
Version 1.3.3 p6
Version 1.3.3 p7
Version 1.3.3 p8
Version 1.3.3 p9
Version 1.3.4
Version 1.3.4 p10
Version 1.3.4 p11
Version 1.3.4 p12
Version 1.3.4 p13
Version 1.3.4 p1
Version 1.3.4 p2
Version 1.3.4 p3
Version 1.3.4 p4
Version 1.3.4 p5
Version 1.3.4 p6
Version 1.3.4 p7
Version 1.3.4 p8
Version 1.3.4 p9
Version 1.3.5
Version 1.3.5 p10
Version 1.3.5 p11
Version 1.3.5 p1
Version 1.3.5 p2
Version 1.3.5 p3
Version 1.3.5 p4
Version 1.3.5 p5
Version 1.3.5 p6
Version 1.3.5 p7
Version 1.3.5 p8
Version 1.3.5 p9
Version 1.4.2
Version 1.4.2 p1
Version 1.4.2 p2
Version 1.4.2 p3
Version 1.4.2 p4
Version 1.4.2 p5
Version 1.4.2 p6
Version 1.5.2
Version 1.5.2 p1
Version 1.5.3 alpha1

References (1)

Timeline

No history available yet.