First published: Tue Nov 02 2021(Updated: )
Improper input validation vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to read files upload via network..
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Nec Clusterpro X | >=1.0<=4.3 | |
Nec Clusterpro X Singleserversafe | >=1.0<=4.3 | |
Nec Expresscluster X | >=1.0<=4.3 | |
Nec Expresscluster X Singleserversafe | >=1.0<=4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20707 is an improper input validation vulnerability in NEC Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, NEC EXPRESSCLUSTER X 4.3 for Windows and earlier, NEC CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, and NEC EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier.
The severity of CVE-2021-20707 is high, with a CVSS score of 7.5.
CVE-2021-20707 affects NEC Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, NEC EXPRESSCLUSTER X 4.3 for Windows and earlier, NEC CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, and NEC EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier.
CVE-2021-20707 is classified under CWE-20: Improper Input Validation.
To fix CVE-2021-20707, it is recommended to update to NEC Transaction Server CLUSTERPRO X version 4.4 or later, NEC EXPRESSCLUSTER X version 4.4 or later, NEC CLUSTERPRO X SingleServerSafe version 4.4 or later, or NEC EXPRESSCLUSTER X SingleServerSafe version 4.4 or later.