First published: Fri Nov 05 2021(Updated: )
Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special configuration is required to exploit this vulnerability.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sitecore Experience Platform (XP) | ||
Sitecore | =7.5 | |
Sitecore | =7.5-update1 | |
Sitecore | =7.5-update2 | |
Sitecore | =8.0 | |
Sitecore | =8.0-sp1 | |
Sitecore | =8.0-update1 | |
Sitecore | =8.0-update2 | |
Sitecore | =8.0-update3 | |
Sitecore | =8.0-update4 | |
Sitecore | =8.0-update5 | |
Sitecore | =8.0-update6 | |
Sitecore | =8.0-update7 | |
Sitecore | =8.1 | |
Sitecore | =8.1-update1 | |
Sitecore | =8.1-update2 | |
Sitecore | =8.1-update3 | |
Sitecore | =8.2 | |
Sitecore | =8.2-update1 | |
Sitecore | =8.2-update2 | |
Sitecore | =8.2-update3 | |
Sitecore | =8.2-update4 | |
Sitecore | =8.2-update5 | |
Sitecore | =8.2-update6 | |
Sitecore | =8.2-update7 | |
=7.5 | ||
=7.5-update1 | ||
=7.5-update2 | ||
=8.0 | ||
=8.0-sp1 | ||
=8.0-update1 | ||
=8.0-update2 | ||
=8.0-update3 | ||
=8.0-update4 | ||
=8.0-update5 | ||
=8.0-update6 | ||
=8.0-update7 | ||
=8.1 | ||
=8.1-update1 | ||
=8.1-update2 | ||
=8.1-update3 | ||
=8.2 | ||
=8.2-update1 | ||
=8.2-update2 | ||
=8.2-update3 | ||
=8.2-update4 | ||
=8.2-update5 | ||
=8.2-update6 | ||
=8.2-update7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-42237 is a vulnerability in Sitecore XP that allows for remote command execution on the machine.
The severity of CVE-2021-42237 is critical with a CVSS score of 9.8.
Sitecore XP versions 7.5 to 8.2 Update-7 are affected by CVE-2021-42237.
No, no authentication or special configuration is required to exploit CVE-2021-42237.
To fix CVE-2021-42237, it is recommended to apply the relevant security patches or updates provided by Sitecore.