Description
Due to the insecure BinaryFormatter deserialization vulnerability in Sitecore XM/XP, an unauthenticated attacker might send a specially-crafted serialized request to execute arbitrary code on the system.
Remediation
Upgrade to the latest version of Sitecore
References
Related Vulnerabilities
MySQL CVE-2017-3650 Vulnerability (CVE-2017-3650)
Oracle HTTP Server Out-of-bounds Write Vulnerability (CVE-2021-4034)
MySQL CVE-2016-0598 Vulnerability (CVE-2016-0598)
Play Framework Out-of-bounds Write Vulnerability (CVE-2020-27196)
IBM WebSEAL Incorrect Authorization Vulnerability (CVE-2023-38368)