EXPOSURES › CVE-2024-34102
CVE-2024-34102
HIGH ⌖ ON CISA KEV · EXPLOITEDAdobe Commerce and Magento Open Source contain an XXE vulnerability that enables remote code execution.
This improperly restricted XXE vulnerability allows remote attackers to execute arbitrary code, posing a severe risk to DIB organizations relying on Adobe Commerce for e-commerce platforms. The vulnerability is actively exploited in the wild, necessitating immediate patching to prevent unauthorized access and data exfiltration.
Shame score — Active exploitation of a known RCE vulnerability in a widely used e-commerce platform indicates a critical security oversight.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Commerce and Magento Open Source contain an improper restriction of XML external entity reference (XXE) vulnerability that allows for remote code execution.
| PRODUCT | STATUS |
|---|---|
| Adobe Acrobat Sign for Government Adobe |
Authorized |
| Adobe Analytics Adobe |
Authorized |
| Adobe Campaign Adobe |
Authorized |
| Adobe Connect Managed Services (ACMS-GC) Adobe |
Authorized |
| Adobe Creative Cloud for Enterprise Adobe |
Authorized |
| Adobe Document Cloud (PDF Services & Adobe Sign) Adobe |
Authorized |
| Adobe Experience Manager Managed Services (AEMMS-GC) Adobe |
Authorized |
| Adobe Learning Manager Adobe |
Authorized |