PT-2025-4482 · Optimizely · Optimizely Configured Commerce

Published

2025-01-04

·

Updated

2025-01-06

·

CVE-2025-22386

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Optimizely Configured Commerce versions prior to 5.2.2408
Description A medium-severity session issue exists in the Commerce B2B application, affecting the longevity of active sessions in the storefront. This allows session tokens tied to logged-out sessions to still be active and usable.
Recommendations For versions prior to 5.2.2408, update to version 5.2.2408 or later to resolve the issue. As a temporary workaround, consider restricting access to active sessions in the storefront to minimize the risk of exploitation.

Fix

Insufficient Session Expiration

Weakness Enumeration

Related Identifiers

CVE-2025-22386

Affected Products

Optimizely Configured Commerce