CVE-2021-42237
KEV
🔴 Łataj teraz
Atak na niebezpieczną deserializację w Sitecore XP umożliwia zdalne wykonanie kodu.
CVSS
9.8
EPSS
97.9%
Exploit
weaponized
Vendor
sitecore
Opis źródłowy (NVD)
Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special configuration is required to exploit this vulnerability.
deserialization exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 9.8 |
| CISA KEV (aktywnie wykorzystywane) | Tak |
| FIRST EPSS (prawdopodobieństwo exploita) | 97.9% |
| Opublikowano (NVD) | 2021-11-05 10:15:08 UTC |
| Ostatnia modyfikacja (NVD) | 2026-07-09 13:57:14 UTC |
Referencje
- http://packetstormsecurity.com/files/164988/Sitecore-Experience-Platform-XP-Remote-Code-Execution.html (cve@mitre.org) [Third Party Advisory, VDB Entry]
- https://blog.assetnote.io/2021/11/02/sitecore-rce/ (cve@mitre.org) [Exploit, Third Party Advisory]
- https://support.sitecore.com/kb?id=kb_article_view&sysparm_article=KB1000776 (cve@mitre.org) [Vendor Advisory]
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-42237 (134c704f-9b21-4f2e-91b3-4a467353bcc0) [US Government Resource]