CISA Known Exploited Vulnerability

CVE-2021-42237 Ransomware

Sitecore · XP

Sitecore XP Remote Command Execution Vulnerability

Date added
BOD 22-01 due date
CWE CWE-502
Ransomware Known

CISA description

Sitcore XP contains an insecure deserialization vulnerability which can allow for remote code execution.

Required action

Apply updates per vendor instructions.