CVE-2022-35692: Adobe Commerce Improper Access Control Security feature bypass
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to leak minor information of another user's account details. Exploitation of this issue does not require user interaction.
Other sources
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to leak minor information of another user's account detials. Exploitation of this issue does not require user interaction.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-35692?
The severity of CVE-2022-35692 is medium with a CVSS score of 5.3.
Which versions of Adobe Commerce are affected by CVE-2022-35692?
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier), and 2.4.4 (and earlier) are affected by CVE-2022-35692.
What is the vulnerability description of CVE-2022-35692?
CVE-2022-35692 is an Improper Access Control vulnerability in Adobe Commerce that could result in a Security feature bypass, allowing an attacker to leak minor information of another user's account.
How can an attacker exploit CVE-2022-35692?
An attacker could exploit CVE-2022-35692 by leveraging the Improper Access Control vulnerability in Adobe Commerce to bypass security features and gain access to another user's account information.
Where can I find more information about CVE-2022-35692?
More information about CVE-2022-35692 can be found at the following reference link: [link](https://helpx.adobe.com/security/products/magento/apsb22-38.html).