8.7
CVE-2025-34139
- EPSS 0.15%
- Veröffentlicht 25.07.2025 16:15:28
- Zuletzt bearbeitet 12.11.2025 20:15:42
- Quelle disclosure@vulncheck.com
- CVE-Watchlists
- Unerledigt
A vulnerability exists in Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud that could allow an unauthenticated attacker to read arbitrary files. This vulnerability affects all Experience Platform topologies (XM, XP, XC) from 8.0 Initial Release through 10.4 Initial Release and later. This issue affects Content Management (CM) and standalone instances. PaaS and containerized solutions are also affected.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerSitecore
≫
Produkt
Experience Manager (XM)
Default Statusunaffected
Version <=
10.4 Initial Release and later
Version
8.0 Initial Release
Status
affected
HerstellerSitecore
≫
Produkt
Experience Platform (XP)
Default Statusunaffected
Version <=
10.4 Initial Release and later
Version
8.0 Initial Release
Status
affected
HerstellerSitecore
≫
Produkt
Experience Commerce (XC)
Default Statusunaffected
Version <=
10.4 Initial Release and later
Version
8.0 Initial Release
Status
affected
HerstellerSitecore
≫
Produkt
Managed Cloud
Default Statusunaffected
Version <=
10.4 Initial Release and later
Version
8.0 Initial Release
Status
affected
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.15% | 0.358 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| disclosure@vulncheck.com | 8.7 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-522 Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
CWE-552 Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.