Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This issue affects Experience Manager (XM): through 9.0; Experience Platform (XP): through 9.0.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Experience_commerce | Sitecore | * | 9.0 (including) |
| Experience_manager | Sitecore | * | 9.0 (including) |
| Experience_platform | Sitecore | * | 9.0 (including) |
| Managed_cloud | Sitecore | - (including) | - (including) |