First published: Sun Sep 15 2024(Updated: )
An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release through 10.4 Initial Release. An unauthenticated attacker can read arbitrary files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sitecore | >=8.0<=10.4 | |
Sitecore CMS and Experience Platform (XP) | >=8.0<=10.4 | |
Sitecore | >=8.0<=10.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-46938 has been classified as a high severity vulnerability due to the potential for unauthorized file access by unauthenticated attackers.
To mitigate CVE-2024-46938, upgrade Sitecore Experience Platform, Experience Manager, and Experience Commerce to versions above 10.4 if currently running on 8.0 through 10.4.
CVE-2024-46938 impacts Sitecore Experience Platform, Experience Manager, and Experience Commerce versions from 8.0 Initial Release through 10.4 Initial Release.
An attacker exploiting CVE-2024-46938 can read arbitrary files on the affected Sitecore installations without requiring authentication.
Currently, the recommended action for CVE-2024-46938 is to upgrade to a secure version as there are no established workarounds.