ZeroHour

CVE-2024-46938

large

Unauthenticated Arbitrary File Read in Sitecore XP, XM, and XC 8.0–10.4

CVSS 3.1
7.5 high
EPSS
47%p99
Published
()
Modified
AI analysis

Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) contain an information-disclosure flaw (CWE-200) that lets an unauthenticated remote attacker read arbitrary files from the server. The issue is triggered over the network with no authentication, no user interaction, and low attack complexity, per the CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N). Successful exploitation yields high-confidence confidentiality impact — exposure of sensitive files such as application configuration and secrets — with no integrity or availability impact. Any organization running the affected versions, spanning 8.0 Initial Release through 10.4 Initial Release, is in scope. The flaw is not yet listed in CISA KEV and no public proof-of-concept is known, but an EPSS of 46.8% (99th percentile) indicates an elevated probability of exploitation within the next 30 days.

What to do: Apply Sitecore's security patch for your version line, upgrading deployments beyond the affected 10.4 Initial Release baseline; since no specific fixed build is stated in the advisory data, consult the vendor advisory for the exact remediated release per version. Until patched, restrict Sitecore management and content-delivery endpoints to trusted networks and review web/application logs for anomalous file-read requests. Given the high EPSS score, prioritize internet-facing instances and monitor for emerging PoC or in-the-wild exploitation.

Affected
Sitecore Experience Platform (XP)8.0 Initial Release through 10.4 Initial Release
Sitecore Experience Manager (XM)8.0 Initial Release through 10.4 Initial Release
Sitecore Experience Commerce (XC)8.0 Initial Release through 10.4 Initial Release
Estimated exposure
largetens of thousands of internet-exposed instances — Sitecore is an enterprise CMS/commerce platform with several thousand corporate customers, and public site-usage trackers and internet-wide scans typically find on the order of tens of thousands of live Sitecore deployments; because the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release through 10.4 Initial Release. An unauthenticated attacker can read arbitrary files.

Vendors
sitecore
Products
experience commerce, experience manager, experience platform
Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.