CVE-2022-35689: Adobe Commerce Improper Access Control Security feature bypass
Adobe Commerce versions 2.4.3-p3 (and earlier), 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the availability of a user's minor feature. Exploitation of this issue does not require user interaction.
Other sources
Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the availability of a user's minor feature. Exploitation of this issue does not require user interaction.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this Adobe Commerce vulnerability?
The vulnerability ID for this Adobe Commerce vulnerability is CVE-2022-35689.
Which versions of Adobe Commerce are affected?
Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected.
What is the severity of CVE-2022-35689?
The severity of CVE-2022-35689 is medium with a CVSS score of 5.3.
What is the impact of CVE-2022-35689?
CVE-2022-35689 could result in a security feature bypass and impact the availability of a user's minor feature.
Where can I find more information about CVE-2022-35689?
You can find more information about CVE-2022-35689 at the following link: [Adobe Security Bulletin APSB22-48](https://helpx.adobe.com/security/products/magento/apsb22-48.html).