Sitecore Experience Manager
cpe:2.3:a:sitecore:experience_manager:*:*:*:*:*:*:*
- >= 10.4.0, < 10.4.1
A remote code execution vulnerability has been identified in Sitecore Experience Manager (XM) and Experience Platform (XP) versions 10.4 prior to KB1002844. This vulnerability arises from insecure deserialization, allowing for unauthorized code execution on the server.
Exploitation of this vulnerability allows for remote code execution on the affected server.
To address this vulnerability, Sitecore users should apply the cumulative hotfix available in KB1002844 for version 10.4. For Managed Cloud customers running affected Experience Platform versions, the same hotfix should be applied. After applying the hotfix, verify that the version of the Sitecore.Kernel assembly is equal to or greater than 19.4.93.21984.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.