QID 14012
Date Published: 2021-11-23
QID 14012: Sitecore Experience Platform Deserialization of Untrusted Data Vulnerability
Sitecore Experience Platform (XP) is an enterprise content management system (CMS).
This issue is related to a remote code execution vulnerability through insecure deserialization in the Report.ashx file. Which is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special configuration is required to exploit this vulnerability.
Affected Versions
Sitecore XP 7.5 Initial Release - Sitecore XP 7.5 Update-2
Sitecore XP 8.0 Initial Release - Sitecore XP 8.0 Update-7
Sitecore XP 8.1 Initial Release - Sitecore XP 8.1 Update-3
Sitecore XP 8.2 Initial Release - Sitecore XP 8.2 Update-7
On successful exploitation an attacker can do remote command execution on the machine.
CVEs related to QID 14012
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| KB1000776 |
|