An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue concerning business logic exists in the Commerce B2B application, which allows storefront visitors to purchase discontinued products in specific scenarios where requests are altered before reaching the server.
References
Link | Resource |
---|---|
https://support.optimizely.com/hc/en-us/articles/32694560473741-Configured-Commerce-Security-Advisory-COM-2024-02 | Vendor Advisory |
Configurations
History
20 May 2025, 20:27
Type | Values Removed | Values Added |
---|---|---|
CWE | NVD-CWE-Other | |
First Time |
Optimizely configured Commerce
Optimizely |
|
Summary |
|
|
CPE | cpe:2.3:a:optimizely:configured_commerce:*:*:*:*:*:*:*:* | |
References | () https://support.optimizely.com/hc/en-us/articles/32694560473741-Configured-Commerce-Security-Advisory-COM-2024-02 - Vendor Advisory |
06 Jan 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
04 Jan 2025, 02:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-01-04 02:15
Updated : 2025-05-20 20:27
NVD link : CVE-2025-22384
Mitre link : CVE-2025-22384
CVE.ORG link : CVE-2025-22384
JSON object : View
Products Affected
optimizely
- configured_commerce
CWE