CVE-2024-39405: Adobe Commerce | Improper Authorization (CWE-285)
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and modify minor information. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39405?
CVE-2024-39405 has a low severity rating due to its potential for security feature bypass by low-privileged attackers.
How do I fix CVE-2024-39405?
To fix CVE-2024-39405, upgrade to Adobe Commerce version 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9, or later.
What products are affected by CVE-2024-39405?
CVE-2024-39405 affects Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier.
What type of vulnerability is CVE-2024-39405?
CVE-2024-39405 is classified as an Improper Authorization vulnerability.
Can low-privileged attackers exploit CVE-2024-39405?
Yes, a low-privileged attacker can leverage CVE-2024-39405 to bypass security measures.