CVE-2024-45132: Adobe Commerce | Incorrect Authorization (CWE-863)
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation. A low-privileged attacker could leverage this vulnerability to bypass security measures and affect confidentiality. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45132?
CVE-2024-45132 has a severity rating that indicates it could lead to privilege escalation.
How do I fix CVE-2024-45132?
To fix CVE-2024-45132, upgrade to the following versions: 2.4.4-p11, 2.4.5-p10, 2.4.6-p8, or 2.4.7-p3.
Which versions of Adobe Commerce are affected by CVE-2024-45132?
Adobe Commerce versions 2.4.4, 2.4.5, 2.4.6, and 2.4.7 prior to their respective patched versions are affected.
What kind of vulnerability is CVE-2024-45132?
CVE-2024-45132 is an Improper Authorization vulnerability that can be exploited by low-privileged attackers.
Can CVE-2024-45132 allow an attacker to escalate privileges?
Yes, CVE-2024-45132 can allow attackers to bypass security controls and escalate their privileges.