PT-2020-6278 · Adobe · Magento

Published

2020-04-28

·

Updated

2024-03-06

·

CVE-2020-9587

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Magento versions 2.3.4 and earlier Magento versions 2.2.11 and earlier Magento versions 1.14.4.4 and earlier Magento versions 1.9.4.4 and earlier
Description The issue is related to an authorization bypass, which could allow a remote attacker to obtain unauthorized discounts on products.
Recommendations For Magento versions 2.3.4 and earlier, update to a version later than 2.3.4 to resolve the issue. For Magento versions 2.2.11 and earlier, update to a version later than 2.2.11 to resolve the issue. For Magento versions 1.14.4.4 and earlier, update to a version later than 1.14.4.4 to resolve the issue. For Magento versions 1.9.4.4 and earlier, update to a version later than 1.9.4.4 to resolve the issue.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BDU:2021-03834
BIT-MAGENTO-2020-9587
CVE-2020-9587
GHSA-8WM7-H2QH-FF4C

Affected Products

Magento