CVE-2021-21957: Command Injection
Published Dec 8, 2021
·Updated
A privilege escalation vulnerability exists in the Remote Server functionality of Dream Report ODS Remote Connector 20.2.16900.0. A specially-crafted command injection can lead to elevated capabilities. An attacker can provide a malicious file to trigger this vulnerability.
Affected Software
1 affected component
Dreamreport Remote Connector=20.2.16900.0
Event History
Dec 8, 2021
CVE Published
via MITRE·09:29 PM
Data Sourced
via MITRE·09:29 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-21957?
CVE-2021-21957 is classified as a privilege escalation vulnerability.
2
How does CVE-2021-21957 impact affected users?
CVE-2021-21957 allows an attacker to execute a specially crafted command that can escalate privileges.
3
What software is affected by CVE-2021-21957?
CVE-2021-21957 affects Dream Report ODS Remote Connector version 20.2.16900.0.
4
How do I fix CVE-2021-21957?
To remediate CVE-2021-21957, update Dream Report ODS Remote Connector to the latest patched version.
5
Can CVE-2021-21957 be exploited remotely?
Yes, CVE-2021-21957 can be exploited remotely through the Remote Server functionality.