7.5
CVE-2024-46938
- EPSS 93.43%
- Veröffentlicht 15.09.2024 22:15:09
- Zuletzt bearbeitet 20.09.2024 18:15:10
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release through 10.4 Initial Release. An unauthenticated attacker can read arbitrary files.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sitecore ≫ Experience Commerce Version >= 8.0 <= 10.4
Sitecore ≫ Experience Manager Version >= 8.0 <= 10.4
Sitecore ≫ Experience Platform Version >= 8.0 <= 10.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 93.43% | 0.998 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.