Junglewise Threat Intelligence

CVE-2021-42237: Sitecore XP Remote Command Execution Vulnerability

CVE-2021-42237 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-03-25

Technologies: Sitecore Experience Platform (XP). Vendors: Sitecore.

Executive brief

Sitecore XP is vulnerable to an insecure deserialization attack that allows for unauthenticated remote command execution. The vulnerability exists in the handling of untrusted data, requiring no special configuration to exploit.

Affected products

  • Sitecore Experience Platform (XP) 7.5 Initial Release to 8.2 Update-7

Timeline

  • 2021-11-02: disclosed: Public disclosure by Assetnote
  • 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-25: exploited: Reported as exploited in the wild