Adobe Framemaker versions 2022.1 and earlier are affected by an Improper Authentication vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass authentication mechanisms and gain unauthorized access. Exploitation of this issue does not require user interaction.
Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin attacker to inject malicious scripts into every admin page. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field, that could be leveraged to gain admin access.
Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. Exploitation of this issue does not require user interaction.
Affected Systems
Affected Versions
This Improper Authorization vulnerability affects all versions prior to the listed fix
versions of Confluence Data Center and Server. Atlassian recommends patching to the
fixed LTS version or later.
Product | Version | Platform |
---|---|---|
Adobe Commerce |
2.4.6-p3 and earlier 2.4.5-p5 and earlier 2.4.4-p6 and earlier 2.4.3-ext-5 and earlier* 2.4.2-ext-5 and earlier* 2.4.1-ext-5 and earlier* 2.4.0-ext-5 and earlier* 2.3.7-p4-ext-5 and earlier* |
All |
Magento Open Source |
2.4.6-p3 and earlier 2.4.5-p5 and earlier 2.4.4-p6 and earlier |
All |
Adobe FrameMaker Publishing Server | Version 2022 Update 1 and earlier versions | Windows |
IoC’s
-
Recommended Solution(s)
Product | Updated Version | Platform | Priority Rating |
---|---|---|---|
Adobe Commerce |
2.4.6-p4 for 2.4.6-p3 and earlier 2.4.5-p6 for 2.4.5-p5 and earlier 2.4.4-p7 for 2.4.4-p6 and earlier 2.4.3-ext-6 for 2.4.3-ext-5 and earlier* 2.4.2-ext-6 for 2.4.2-ext-5 and earlier* 2.4.1-ext-6 for 2.4.1-ext-5 and earlier* 2.4.0-ext-6 for 2.4.0-ext-5 and earlier* 2.3.7-p4-ext-6 for 2.3.7-p4-ext-5 and earlier* |
All | 3 |
Magento Open Source |
2.4.6-p4 for 2.4.6-p3 and earlier 2.4.5-p6 for 2.4.5-p5 and earlier 2.4.4-p7 for 2.4.4-p6 and earlier |
All | 3 |
Product | Version | Platform | Priority | Availability |
---|---|---|---|---|
Adobe FrameMaker Publishing Server | Version 2022.2 | Windows | 3 | Tech Note |
CVE / CWE
CVE-2024-20719
CVE-2024-20720
CVE-2024-20738
Related Website(s)
* Vulnerabilities with a CVSS 3.1 score between 7.0 and 8.9 are evaluated to be “high” whereas vulnerabilities with a CVSS 3.1 score between 9.0 and 10.0 are evaluated to be “critical”.
+90 216 504 53 32
Aydınevler Mahallesi,İsmet İnönü Cadddesi,Küçükyalı Ofis Park A Blok,No:20/1 Maltepe İstanbul
+90 312 235 44 51
You can register to our newsletter on the home page to be instantly informed about security vulnerabilities.