CVE-2021-42237
experience platform
Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special configuration is required to exploit this vulnerability.
- CVSS
- 9.8
- EPSS
- 97.9% 99.9% percentile
- CISA KEV
- Listed
- Published
- 2021.11.05