Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Insufficiently Protected Credentials vulnerability that could lead to a security feature bypass. A high privileged attacker could exploit this vulnerability to gain unauthorized access to protected resources by obtaining sensitive credential information. Exploitation of this issue does not require user interaction.
History

Tue, 08 Apr 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Apr 2025 20:30:00 +0000

Type Values Removed Values Added
Description Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Insufficiently Protected Credentials vulnerability that could lead to a security feature bypass. A high privileged attacker could exploit this vulnerability to gain unauthorized access to protected resources by obtaining sensitive credential information. Exploitation of this issue does not require user interaction.
Title Adobe Commerce | Insufficiently Protected Credentials (CWE-522)
Weaknesses CWE-522
References
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published: 2025-04-08T20:17:10.679Z

Updated: 2025-04-08T21:01:36.000Z

Reserved: 2025-02-19T22:28:19.021Z

Link: CVE-2025-27192

cve-icon Vulnrichment

Updated: 2025-04-08T20:55:20.801Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-08T21:15:51.040

Modified: 2025-04-09T20:02:41.860

Link: CVE-2025-27192

cve-icon Redhat

No data.