CVE-2019-7846: High severity adobe campaign vulnerability
Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Improper error handling vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user.
Other sources
PRODSECBUG-1513: Insufficient brute force protections on promo code entry
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-7846.
What is the title of this vulnerability?
The title of this vulnerability is PRODSECBUG-1513: Insufficient brute force protections on promo code entry.
Which software versions are affected by this vulnerability?
The software versions affected by this vulnerability are Magento 2.1 up to 2.1.18, Magento 2.2 up to 2.2.9, and Magento 2.3 up to 2.3.2.
What is the recommended action to fix this vulnerability?
The recommended action to fix this vulnerability is to apply the security update provided by Magento: https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-33.
Are there any brute force protections missing in the promo code entry feature?
Yes, there are insufficient brute force protections on the promo code entry feature.