All CVEs View on NVD
CVE-2021-42237
CRITICAL9.8
CISA KEV
Published 2021-11-05 · Updated 2026-07-09 · Source cve@mitre.org
Description
Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special configuration is required to exploit this vulnerability.
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-502CWE-502
CISA Known-Exploited Vulnerability
Product: Sitecore — XP
Name: Sitecore XP Remote Command Execution Vulnerability
Date added: 2022-03-25 · Due: 2022-04-15
USED IN RANSOMWARE
Required action: Apply updates per vendor instructions.
References
- http://packetstormsecurity.com/files/164988/Sitecore-Experience-Platform-XP-Remote-Code-Execution.html
- https://blog.assetnote.io/2021/11/02/sitecore-rce/
- https://support.sitecore.com/kb?id=kb_article_view&sysparm_article=KB1000776
- http://packetstormsecurity.com/files/164988/Sitecore-Experience-Platform-XP-Remote-Code-Execution.html
- https://blog.assetnote.io/2021/11/02/sitecore-rce/
- https://support.sitecore.com/kb?id=kb_article_view&sysparm_article=KB1000776
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-42237

