CVE-2021-36037: Magento Commerce Improper Authorization Vulnerability Could Lead To Information Exposure
Published Sep 1, 2021
·Updated
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper improper authorization vulnerability. An authenticated attacker could leverage this vulnerability to achieve sensitive information disclosure.
Affected Software
6 affected components
Adobe Adobe Commerce>=2.3.0<=2.3.7
Adobe Adobe Commerce>=2.4.0<=2.4.2
Adobe Adobe Commerce=2.4.2-p1
Adobe Magento Open Source>=2.3.0<=2.3.7
Adobe Magento Open Source>=2.4.0<=2.4.2
Adobe Magento Open Source=2.4.2-p1
Remediation
Event History
Sep 1, 2021
CVE Published
via MITRE·02:28 PM
Data Sourced
via MITRE·02:28 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-36037.
2
Which versions of Magento Commerce are affected?
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier), and 2.3.7 (and earlier) are affected.
3
What is the severity of CVE-2021-36037?
The severity of CVE-2021-36037 is medium with a CVSS score of 6.5.
4
How can an attacker leverage this vulnerability?
An authenticated attacker could leverage this vulnerability to achieve sensitive information disclosure.
5
Where can I find more information about CVE-2021-36037?
You can find more information about CVE-2021-36037 at the following link: [CVE-2021-36037](https://helpx.adobe.com/security/products/magento/apsb21-64.html).