← Back

CVE-2021-42237

Published: Nov 5, 2021Modified: Nov 10, 2025CISA KEV

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special configuration is required to exploit this vulnerability.

Affected (24)

1 product
Experience Platform
Configuration A
24 vulnerable
Vulnerable SoftwareAffected Versions
Sitecore
Version 7.5
Version 7.5 update1
Version 7.5 update2
Version 8.0
Version 8.0 sp1
Version 8.0 update1
Version 8.0 update2
Version 8.0 update3
Version 8.0 update4
Version 8.0 update5
Version 8.0 update6
Version 8.0 update7
Version 8.1
Version 8.1 update1
Version 8.1 update2
Version 8.1 update3
Version 8.2
Version 8.2 update1
Version 8.2 update2
Version 8.2 update3
Version 8.2 update4
Version 8.2 update5
Version 8.2 update6
Version 8.2 update7

References (9)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.