CVE-2023-35814: Critical severity devexpress xtrareports vulnerability
Published Apr 28, 2025
·Updated
DevExpress before 23.1.3 does not properly protect XtraReport serialized data in ASP.NET web forms.
Affected Software
5 affected components
DevExpress XtraReport<23.1.3
DevExpress DevExpress<21.2.12
DevExpress DevExpress=22.1.8
DevExpress DevExpress=22.2.4
DevExpress DevExpress=22.2.5
Event History
Apr 28, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-35814?
CVE-2023-35814 is classified as a high severity vulnerability due to its impact on data protection.
2
How do I fix CVE-2023-35814?
To fix CVE-2023-35814, upgrade to DevExpress XtraReports version 23.1.3 or later.
3
What are the potential impacts of CVE-2023-35814?
The vulnerability can lead to unauthorized access to sensitive serialized data within ASP.NET web forms.
4
Which versions of DevExpress XtraReports are affected by CVE-2023-35814?
CVE-2023-35814 affects all versions of DevExpress XtraReports prior to 23.1.3.
5
Is CVE-2023-35814 related to data serialization issues?
Yes, CVE-2023-35814 involves improper protection of serialized data in the XtraReports library.