CVE-2021-42237
CVE Published | 2021-11-05 |
---|---|
Related CWE(s) | CWE-502: Deserialization of Untrusted Data |
Related Vendor(s) | sitecore |
Related Product(s) | experience_platform |
Exploitation Reported (CISA KEV) | 2022-03-25 |
CVSS 3 Base Score | 9.8 (CRITICAL) |
CVSS 3 Attack Complexity | LOW |
CVSS 3 Attack Vector | NETWORK |
Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special configuration is required to exploit this vulnerability.
Cyber Threat Graph Context
Explore how this CVE relates to the wider threat graph