CVE-2019-11080: Critical severity sitecore vulnerability
Sitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization, aka TFS # 293863. An authenticated user with necessary permissions is able to remotely execute OS commands by sending a crafted serialized object.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2019-11080.
What is the title of the vulnerability?
The title of the vulnerability is 'Sitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization.'
What is the severity of CVE-2019-11080?
The severity of CVE-2019-11080 is critical with a severity value of 8.8.
How does the vulnerability occur?
The vulnerability occurs when an authenticated user with necessary permissions sends a crafted serialized object, allowing remote execution of OS commands.
How can I fix CVE-2019-11080?
To fix CVE-2019-11080, it is recommended to upgrade Sitecore Experience Platform (XP) to version 9.1.1 or later.