CVE-2021-42237

KEV
🔴 Łataj teraz

Atak na niebezpieczną deserializację w Sitecore XP umożliwia zdalne wykonanie kodu.

CVSS
9.8
EPSS
97.9%
Exploit
weaponized
Vendor
sitecore
Opis źródłowy (NVD)

Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special configuration is required to exploit this vulnerability.

deserialization exploit Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS9.8
CISA KEV (aktywnie wykorzystywane)Tak
FIRST EPSS (prawdopodobieństwo exploita)97.9%
Opublikowano (NVD)2021-11-05 10:15:08 UTC
Ostatnia modyfikacja (NVD)2026-07-09 13:57:14 UTC
Referencje