← Zuruck zu CVEs
CVE-2022-24086
CRITICALCISA KEV9.8
Beschreibung
Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution.
CVE Details
CVSS v3.1 Bewertung9.8
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht2/16/2022
Zuletzt geandert10/23/2025
Quellekev
Honeypot-Sichtungen0
CISA KEV
HerstellerAdobe
ProduktCommerce and Magento Open Source
SchwachstellennameAdobe Commerce and Magento Open Source Improper Input Validation Vulnerability
KEV Aufnahmedatum2022-02-15
Behebungsfrist2022-03-01
Ransomware-NutzungUnknown
Betroffene Produkte
adobe:commerceadobe:magento
Schwachen (CWE)
CWE-20
Referenzen
https://helpx.adobe.com/security/products/magento/apsb22-12.html(psirt@adobe.com)
https://helpx.adobe.com/security/products/magento/apsb22-12.html(af854a3a-2127-422b-91ae-364da2661108)
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-24086(134c704f-9b21-4f2e-91b3-4a467353bcc0)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.