Intrusion Prevention

Magento.Forwarded.Parameter.Authentication.Bypass

Description

This indicates an attack attempt to exploit an Authentication Bypass vulnerability in e-commerce platform Magento.
The vulnerability is due to improper authentication of incoming request. A remote attacker may be able to exploit this to execute arbitrary code execution against the affected machine, via a crafted request.

Affected Products

Magento Magento 1.14.1.0 EE
Magento Magento 1.9.1.0 CE

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Recommended Actions

Currently we are unaware of any vendor supplied patch for this issue

CVE References

CVE-2015-3457