« Volver al listado

CVE-2022-42344

Estado: ModificadaAlta (8.8)—

Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Incorrect Authorization vulnerability. An authenticated attacker can exploit this vulnerability to achieve information exposure and privilege escalation.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-42344",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@adobe.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@adobe.com",
      "affectedData": [
        {
          "vendor": "Adobe",
          "product": "Adobe Commerce",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "semver",
              "lessThanOrEqual": "2.4.3-p2"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2022-10-20T17:15:10.723",
  "references": [
    {
      "url": "https://helpx.adobe.com/security/products/magento/apsb22-38.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@adobe.com"
    },
    {
      "url": "https://helpx.adobe.com/security/products/magento/apsb22-38.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@adobe.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-863"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-863"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Incorrect Authorization vulnerability. An authenticated attacker can exploit this vulnerability to achieve information exposure and privilege escalation."
    },
    {
      "lang": "es",
      "value": "Adobe Commerce versiones 2.4.3-p2 (y anteriores), 2.3.7-p3 (y anteriores) y 2.4.4 (y anteriores) están afectadas por una vulnerabilidad de comprobación de entrada inapropiada. Un atacante autenticado puede desencadenar una referencia de objeto directa insegura en el endpoint \"V1/customers/me\" para lograr una exposición de información y una escalada de privilegios"
    }
  ],
  "lastModified": "2026-06-17T05:04:45.923",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:adobe:commerce:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9D3D4DD8-EBF6-4281-B103-CB85CFCAA4C0",
              "versionEndExcluding": "2.3.7"
            },
            {
              "criteria": "cpe:2.3:a:adobe:commerce:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BF96C367-576B-437B-A86C-CB9CA65CB481",
              "versionEndExcluding": "2.4.3",
              "versionStartIncluding": "2.4.0"
            },
            {
              "criteria": "cpe:2.3:a:adobe:commerce:2.3.7:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4346BF61-743B-4BBE-AC90-9954FEE6E943"
            },
            {
              "criteria": "cpe:2.3:a:adobe:commerce:2.3.7:p1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9F471E19-8AFE-4A6C-88EA-DF94428518F7"
            },
            {
              "criteria": "cpe:2.3:a:adobe:commerce:2.3.7:p2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "27E5B990-1E1C-46AC-815F-AF737D211C16"
            },
            {
              "criteria": "cpe:2.3:a:adobe:commerce:2.3.7:p3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8D1598F4-AA41-4F94-A986-E603DC42AC8B"
            },
            {
              "criteria": "cpe:2.3:a:adobe:commerce:2.4.3:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7B503C35-8C90-4A24-8E60-722CDBBF556B"
            },
            {
              "criteria": "cpe:2.3:a:adobe:commerce:2.4.3:p1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8A453C85-A14A-47B8-B91D-3906BBE42A78"
            },
            {
              "criteria": "cpe:2.3:a:adobe:commerce:2.4.3:p2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "38FFC3BA-B75E-4060-9E29-74367C7BE8A8"
            },
            {
              "criteria": "cpe:2.3:a:adobe:commerce:2.4.4:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D258D9EF-94FB-41F0-A7A5-7F66FA7A0055"
            },
            {
              "criteria": "cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9DF037A1-026B-4083-97FB-13578A56326C",
              "versionEndExcluding": "2.3.7"
            },
            {
              "criteria": "cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B865822D-748C-420A-A116-9A2254A11D75",
              "versionEndExcluding": "2.4.3",
              "versionStartIncluding": "2.4.0"
            },
            {
              "criteria": "cpe:2.3:a:magento:magento:2.3.7:-:*:*:open_source:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4F1E5426-A646-4EC1-902A-FD30B00AD1AA"
            },
            {
              "criteria": "cpe:2.3:a:magento:magento:2.3.7:p1:*:*:open_source:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E1D29DD6-93EA-4740-96FE-032AA219D1E7"
            },
            {
              "criteria": "cpe:2.3:a:magento:magento:2.3.7:p2:*:*:open_source:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "97FC8827-5A1E-4F5B-AE87-77B32D4309AD"
            },
            {
              "criteria": "cpe:2.3:a:magento:magento:2.3.7:p3:*:*:open_source:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "091B6125-E08F-430B-8F7C-AF99AB525CE8"
            },
            {
              "criteria": "cpe:2.3:a:magento:magento:2.4.3:-:*:*:open_source:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "21DC0F2F-D401-45C3-A4BC-B3C34BFD84B7"
            },
            {
              "criteria": "cpe:2.3:a:magento:magento:2.4.3:p1:*:*:open_source:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3ECBE809-A545-40B7-892C-ACEBFC76E886"
            },
            {
              "criteria": "cpe:2.3:a:magento:magento:2.4.3:p2:*:*:open_source:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "360125BA-CA99-41D7-BA88-6FA4372A4BFB"
            },
            {
              "criteria": "cpe:2.3:a:magento:magento:2.4.4:-:*:*:open_source:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3F7E6786-3F2D-40AA-9C2A-4B6E1391C379"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@adobe.com"
}