CVE-2021-36483
CVE-2021-36483
DevExpress.XtraReports.UI through v21.1 allows attackers to execute arbitrary code via insecure deserialization.
Productos afectados
n/a · n/a¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
https://gist.github.com/tree-chtsec/27013ed6cb297b24e44f6359439b678ehttps://supportcenter.devexpress.com/ticket/details/t1031535/reporting-unsafe-data-type-deserializationhttps://supportcenter.devexpress.com/ticket/details/t708194/net-web-controls-unsafe-data-type-deserializationhttps://supportcenter.devexpress.com/ticket/details/t714296/net-desktop-controls-unsafe-data-type-deserializationhttps://www.chtsecurity.com/news/a01d1bc6-19c8-4187-b343-6bc685efe64fhttps://www.zerodayinitiative.com/advisories/ZDI-22-341/