Impact
Adobe Commerce is affected by an Information Exposure vulnerability that can lead to a limited disclosure of sensitive data. The weakness is classified as CWE-200 and does not require user interaction to be exploited. Exploitation of this issue depends on conditions beyond the attacker’s direct control, indicating that the vulnerability is not easily reproducible by a generic attacker. The potential impact is the inadvertent exposure of data that could aid further attacks, but the scope is limited to information that is inadvertently revealed by the affected systems.
Affected Systems
Affected products include Adobe Commerce, Adobe Commerce B2B, Adobe Commerce Webhooks Plugin, and Adobe Magento Open Source. No specific version information was provided for the vulnerability, so all released versions of the listed products should be considered potentially impacted until a patch is released.
Risk and Exploitability
The CVSS score of 3.7 indicates a low overall severity, and the EPSS score of less than 1% suggests that an exploit is unlikely to be observed in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote access to a component that inadvertently exposes data, although no explicit network path is detailed in the advisory. The dependency on external conditions means the risk of exploitation today is very low, but continuous monitoring for new findings is advised.
OpenCVE Enrichment