Adobe Commerce B2B vulnerabilities

96 known vulnerabilities affecting adobe/commerce_b2b.

Total CVEs
96
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH32MEDIUM50LOW11

Vulnerabilities

Page 5 of 5
CVE-2024-45130MEDIUMCVSS 4.3v1.3.3v1.3.4+2 more2024-10-10
CVE-2024-45130 [MEDIUM] CWE-284 CVE-2024-45130: Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Impro Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and have a low impact on integrity. Exploitation of this issue does not require us
nvd
CVE-2024-45132MEDIUMCVSS 6.5v1.3.3v1.3.4+2 more2024-10-10
CVE-2024-45132 [MEDIUM] CWE-863 CVE-2024-45132: Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Impro Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation. A low-privileged attacker could leverage this vulnerability to bypass security measures and affect confidentiality. Exploitation of this issue does not require user interaction
nvd
CVE-2024-45122MEDIUMCVSS 4.3v1.3.3v1.3.4+2 more2024-10-10
CVE-2024-45122 [MEDIUM] CWE-284 CVE-2024-45122: Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Impro Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and have a low impact on confidentiality. Exploitation of this issue does not requ
nvd
CVE-2024-45119MEDIUMCVSS 4.9v1.3.3v1.3.4+2 more2024-10-10
CVE-2024-45119 [MEDIUM] CWE-918 CVE-2024-45119: Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 (and earlier) are affected by a Serv Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. An admin-privilege authenticated attacker can force the application to make arbitrary requests via injection of arbitrary URLs. Exploitation of this issue does
nvd
CVE-2024-45127MEDIUMCVSS 4.8v1.3.3v1.3.4+2 more2024-10-10
CVE-2024-45127 [MEDIUM] CWE-79 CVE-2024-45127: Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a stored Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerab
nvd
CVE-2024-45129MEDIUMCVSS 4.3v1.3.3v1.3.4+2 more2024-10-10
CVE-2024-45129 [MEDIUM] CWE-284 CVE-2024-45129: Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Impro Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in Privilege escalation. A low-privileged attacker could leverage this vulnerability to bypass security measures and have a low impact on integrity. Exploitation of this issue does not require user in
nvd
CVE-2024-45121MEDIUMCVSS 4.3v1.3.3v1.3.4+2 more2024-10-10
CVE-2024-45121 [MEDIUM] CWE-284 CVE-2024-45121: Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Impro Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and have a low impact on integrity. Exploitation of this issue does not require us
nvd
CVE-2024-45131MEDIUMCVSS 5.4v1.3.3v1.3.4+2 more2024-10-10
CVE-2024-45131 [MEDIUM] CWE-863 CVE-2024-45131: Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Impro Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and have a low impact on confidentiality and integrity. Exploitation of this issue
nvd
CVE-2024-45124MEDIUMCVSS 5.3v1.3.3v1.3.4+2 more2024-10-10
CVE-2024-45124 [MEDIUM] CWE-284 CVE-2024-45124: Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Impro Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and have a low impact on integrity. Exploitation of this issue does not require user interaction
nvd
CVE-2024-45125MEDIUMCVSS 4.3v1.3.3v1.3.4+2 more2024-10-10
CVE-2024-45125 [MEDIUM] CWE-863 CVE-2024-45125: Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Incor Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could exploit this vulnerability to have a low impact on integrity. Exploitation of this issue does not require user interaction.
nvd
CVE-2024-45118MEDIUMCVSS 6.5v1.3.3v1.3.4+2 more2024-10-10
CVE-2024-45118 [MEDIUM] CWE-284 CVE-2024-45118: Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Impro Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and have high impact on integrity. Exploitation of this issue does not require use
nvd
CVE-2024-45120LOWCVSS 3.1v1.3.3v1.3.4+2 more2024-10-10
CVE-2024-45120 [LOW] CWE-367 CVE-2024-45120: Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a Time-o Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could lead to a security feature bypass. An attacker could exploit this vulnerability to alter a condition between the check and the use of a resource, having a low impact on integrity. Explo
nvd
CVE-2024-45149LOWCVSS 2.7v1.3.3v1.3.4+2 more2024-10-10
CVE-2024-45149 [LOW] CWE-284 CVE-2024-45149: Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Impro Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security measures and have a low impact on confidentiality. Exploitation of this issue does not requir
nvd
CVE-2024-45133LOWCVSS 2.7v1.3.3v1.3.4+2 more2024-10-10
CVE-2024-45133 [LOW] CWE-284 CVE-2024-45133: Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Infor Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Information Exposure vulnerability that could result in a security feature bypass. An admin attacker could leverage this vulnerability to have a low impact on confidentiality which may aid in further attacks. Exploitation of this issue does not require user i
nvd
CVE-2024-45135LOWCVSS 2.7v1.3.3v1.3.4+2 more2024-10-10
CVE-2024-45135 [LOW] CWE-284 CVE-2024-45135: Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Impro Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An admin attacker could leverage this vulnerability to bypass security measures and have a low impact on integrity. Exploitation of this issue does not require user interact
nvd
CVE-2024-45134LOWCVSS 2.7v1.3.3v1.3.4+2 more2024-10-10
CVE-2024-45134 [LOW] CWE-200 CVE-2024-45134: Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Infor Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Information Exposure vulnerability that could result in a security feature bypass. An admin attacker could leverage this vulnerability to have a low impact on confidentiality which may aid in further attacks. Exploitation of this issue does not require user i
nvd