CyberSec.Space Logo
Back to CVE Browser

CVE-2021-42237

Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
EPSS Score58.7780%
EPSS Percentile88.26th
PublishedNov 5, 2021
Last ModifiedNov 10, 2025

Vulnerability Description

Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special configuration is required to exploit this vulnerability.

Affected Platforms (CPE)

πŸ“¦
Sitecore

Experience Platform

= 7.5
πŸ“¦
Sitecore

Experience Platform

= 7.5
πŸ“¦
Sitecore

Experience Platform

= 7.5
πŸ“¦
Sitecore

Experience Platform

= 8.0
πŸ“¦
Sitecore

Experience Platform

= 8.0
πŸ“¦
Sitecore

Experience Platform

= 8.0
πŸ“¦
Sitecore

Experience Platform

= 8.0
πŸ“¦
Sitecore

Experience Platform

= 8.0
πŸ“¦
Sitecore

Experience Platform

= 8.0
πŸ“¦
Sitecore

Experience Platform

= 8.0
πŸ“¦
Sitecore

Experience Platform

= 8.0
πŸ“¦
Sitecore

Experience Platform

= 8.0
πŸ“¦
Sitecore

Experience Platform

= 8.1
πŸ“¦
Sitecore

Experience Platform

= 8.1
πŸ“¦
Sitecore

Experience Platform

= 8.1
πŸ“¦
Sitecore

Experience Platform

= 8.1
πŸ“¦
Sitecore

Experience Platform

= 8.2
πŸ“¦
Sitecore

Experience Platform

= 8.2
πŸ“¦
Sitecore

Experience Platform

= 8.2
πŸ“¦
Sitecore

Experience Platform

= 8.2
πŸ“¦
Sitecore

Experience Platform

= 8.2
πŸ“¦
Sitecore

Experience Platform

= 8.2
πŸ“¦
Sitecore

Experience Platform

= 8.2
πŸ“¦
Sitecore

Experience Platform

= 8.2

References & Advisories

Related Vulnerabilities