CVE-2021-42237

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
05/11/2021
Last modified:
03/04/2025

Description

Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special configuration is required to exploit this vulnerability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sitecore:experience_platform:7.5:-:*:*:*:*:*:*
cpe:2.3:a:sitecore:experience_platform:7.5:update1:*:*:*:*:*:*
cpe:2.3:a:sitecore:experience_platform:7.5:update2:*:*:*:*:*:*
cpe:2.3:a:sitecore:experience_platform:8.0:-:*:*:*:*:*:*
cpe:2.3:a:sitecore:experience_platform:8.0:sp1:*:*:*:*:*:*
cpe:2.3:a:sitecore:experience_platform:8.0:update1:*:*:*:*:*:*
cpe:2.3:a:sitecore:experience_platform:8.0:update2:*:*:*:*:*:*
cpe:2.3:a:sitecore:experience_platform:8.0:update3:*:*:*:*:*:*
cpe:2.3:a:sitecore:experience_platform:8.0:update4:*:*:*:*:*:*
cpe:2.3:a:sitecore:experience_platform:8.0:update5:*:*:*:*:*:*
cpe:2.3:a:sitecore:experience_platform:8.0:update6:*:*:*:*:*:*
cpe:2.3:a:sitecore:experience_platform:8.0:update7:*:*:*:*:*:*
cpe:2.3:a:sitecore:experience_platform:8.1:-:*:*:*:*:*:*
cpe:2.3:a:sitecore:experience_platform:8.1:update1:*:*:*:*:*:*
cpe:2.3:a:sitecore:experience_platform:8.1:update2:*:*:*:*:*:*