First published: Wed Aug 04 2021(Updated: )
DevExpress.XtraReports.UI through v21.1 allows attackers to execute arbitrary code via insecure deserialization.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
openMairie Openpresse | <=21.1 | |
openMairie Openpresse |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-36483 is considered a critical vulnerability due to its potential to allow arbitrary code execution.
To fix CVE-2021-36483, update DevExpress XtraReports to version 21.2 or later, which addresses this insecure deserialization issue.
CVE-2021-36483 affects installations of DevExpress XtraReports up to version 21.1.
CVE-2021-36483 allows remote attackers to execute arbitrary code on affected systems through insecure deserialization.
Yes, authentication is required to exploit CVE-2021-36483.