Description
Due to the insecure BinaryFormatter deserialization vulnerability in Sitecore XM/XP, an unauthenticated attacker might send a specially-crafted serialized request to execute arbitrary code on the system.
Remediation
Upgrade to the latest version of Sitecore
References
Related Vulnerabilities
XWiki Missing Authorization Vulnerability (CVE-2022-36091)
TYPO3 Improper Input Validation Vulnerability (CVE-2010-5099)
Oracle JRE CVE-2013-5840 Vulnerability (CVE-2013-5840)
XWiki Improper Authentication Vulnerability (CVE-2022-36093)
WebERP Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2018-20420)