Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-18524 | Sitecore Experience Manager (XM) and Experience Platform (XP) versions 10.1 to 10.1.4 rev. 011974 PRE, all versions of 10.2, 10.3 to 10.3.3 rev. 011967 PRE, and 10.4 to 10.4.1 rev. 011941 PRE contain a hardcoded user account. Unauthenticated and remote attackers can use this account to access administrative API over HTTP. |
Solution
Update to patched versions.
Workaround
No workaround given by the vendor.
Mon, 08 Sep 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sitecore experience Commerce
Sitecore managed Cloud |
|
| CPEs | cpe:2.3:a:sitecore:experience_commerce:*:*:*:*:*:*:*:* cpe:2.3:a:sitecore:experience_manager:*:*:*:*:*:*:*:* cpe:2.3:a:sitecore:experience_platform:*:*:*:*:*:*:*:* cpe:2.3:a:sitecore:experience_platform:10.4:-:*:*:*:*:*:* cpe:2.3:a:sitecore:managed_cloud:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Sitecore experience Commerce
Sitecore managed Cloud |
Tue, 22 Jul 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 17 Jun 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 17 Jun 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Tue, 17 Jun 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Sitecore Experience Manager (XM) and Experience Platform (XP) versions 10.1 to 10.1.4 rev. 011974 PRE, all versions of 10.2, 10.3 to 10.3.3 rev. 011967 PRE, and 10.4 to 10.4.1 rev. 011941 PRE contain a hardcoded user account. Unauthenticated and remote attackers can use this account to access administrative API over HTTP. | |
| Title | Sitecore XM and XP Hardcoded Credentials | |
| Weaknesses | CWE-798 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-07-22T13:07:15.476Z
Reserved: 2025-04-15T19:15:22.612Z
Link: CVE-2025-34509
Updated: 2025-06-17T19:04:47.633Z
Status : Analyzed
Published: 2025-06-17T19:15:31.423
Modified: 2025-09-08T19:17:06.773
Link: CVE-2025-34509
No data.
OpenCVE Enrichment
Updated: 2025-06-20T13:55:53Z
EUVD