8.7

CVE-2025-34139

Sitecore XM/XP/XC and Managed Cloud 8.0 - 10.4 Arbitrary File Read

A vulnerability exists in Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud that could allow an unauthenticated attacker to read arbitrary files. This vulnerability affects all Experience Platform topologies (XM, XP, XC) from 8.0 Initial Release through 10.4 Initial Release and later. This issue affects Content Management (CM) and standalone instances. PaaS and containerized solutions are also affected.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerSitecore
Produkt Experience Manager (XM)
Default Statusunaffected
Version <= 10.4 Initial Release and later
Version 8.0 Initial Release
Status affected
HerstellerSitecore
Produkt Experience Platform (XP)
Default Statusunaffected
Version <= 10.4 Initial Release and later
Version 8.0 Initial Release
Status affected
HerstellerSitecore
Produkt Experience Commerce (XC)
Default Statusunaffected
Version <= 10.4 Initial Release and later
Version 8.0 Initial Release
Status affected
HerstellerSitecore
Produkt Managed Cloud
Default Statusunaffected
Version <= 10.4 Initial Release and later
Version 8.0 Initial Release
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.46% 0.367
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
disclosure@vulncheck.com 8.7 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-522 Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

CWE-552 Files or Directories Accessible to External Parties

The product makes files or directories accessible to unauthorized actors, even though they should not be.

https://support.sitecore.com/kb?id=kb_article_view&sysparm_article=KB1003650
https://support.sitecore.com/kb?id=kb_article_view&sysparm_article=KB1003661
https://www.vulncheck.com/advisories/sitecore-xm-xp-xc-managed-cloud-arbitrary-file-read