Adobe Security Vulnerabilities

Adobe Security Vulnerabilities

Adobe Framemaker versions 2022.1 and earlier are affected by an Improper Authentication vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass authentication mechanisms and gain unauthorized access. Exploitation of this issue does not require user interaction.

Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin attacker to inject malicious scripts into every admin page. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field, that could be leveraged to gain admin access.

Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. Exploitation of this issue does not require user interaction.

Adobe Security Vulnerabilities

Affected Systems

Affected Versions
This Improper Authorization vulnerability affects all versions prior to the listed fix versions of Confluence Data Center and Server. Atlassian recommends patching to the fixed LTS version or later.

Product Version Platform
Adobe Commerce 2.4.6-p3 and earlier
2.4.5-p5 and earlier
2.4.4-p6 and earlier
2.4.3-ext-5 and earlier*
2.4.2-ext-5 and earlier*
2.4.1-ext-5 and earlier*
2.4.0-ext-5 and earlier*
2.3.7-p4-ext-5 and earlier*
All
Magento Open Source 2.4.6-p3 and earlier
2.4.5-p5 and earlier
2.4.4-p6 and earlier
All
Adobe FrameMaker Publishing Server Version 2022 Update 1 and earlier versions Windows

IoC’s

-

Recommended Solution(s)

Product Updated Version Platform Priority Rating
Adobe Commerce 2.4.6-p4 for 2.4.6-p3 and earlier
2.4.5-p6 for 2.4.5-p5 and earlier
2.4.4-p7 for 2.4.4-p6 and earlier
2.4.3-ext-6 for 2.4.3-ext-5 and earlier*
2.4.2-ext-6 for 2.4.2-ext-5 and earlier*
2.4.1-ext-6 for 2.4.1-ext-5 and earlier*
2.4.0-ext-6 for 2.4.0-ext-5 and earlier*
2.3.7-p4-ext-6 for 2.3.7-p4-ext-5 and earlier*
All 3
Magento Open Source 2.4.6-p4 for 2.4.6-p3 and earlier
2.4.5-p6 for 2.4.5-p5 and earlier
2.4.4-p7 for 2.4.4-p6 and earlier
All 3
Product Version Platform Priority Availability
Adobe FrameMaker Publishing Server Version 2022.2 Windows 3 Tech Note

CVE / CWE

CVE-2024-20719
CVE-2024-20720
CVE-2024-20738

Related Website(s)

* Vulnerabilities with a CVSS 3.1 score between 7.0 and 8.9 are evaluated to be “high” whereas vulnerabilities with a CVSS 3.1 score between 9.0 and 10.0 are evaluated to be “critical”.