PT-2021-5577 · Sitecore · Sitecore Xp

Shubham Shah

·

Published

2021-10-08

·

Updated

2025-11-10

·

CVE-2021-42237

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Sitecore XP versions 7.5 Initial Release through 8.2 Update-7
Description The issue is related to an insecure deserialization attack that can lead to remote command execution on the machine. No authentication or special configuration is required to exploit this vulnerability. It is reported that the Australian Department of Defence's ForceNet platform, which uses Sitecore XP, was affected by a ransomware attack, potentially exposing 30,000 to 40,000 personal records. However, it is not confirmed if this incident is directly related to the vulnerability in question.
Recommendations For Sitecore XP versions 7.5 Initial Release through 8.2 Update-7, update to a secure version, ideally Sitecore XP 9.0 or higher. As a temporary workaround, consider removing the Report.ashx file from /sitecore/shell/ClientBin/Reporting/ on all server instances to minimize the risk of exploitation.

Exploit

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BDU:2022-00003
CVE-2021-42237

Affected Products

Sitecore Xp