Back to Database
Status published
Low
CVE-2023-35815
DevExpress before 23.1.3 has a data-source protection mechanism bypass during...
Vulnerability Description
DevExpress before 23.1.3 has a data-source protection mechanism bypass during deserialization on XML data.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-35815
Credits & Attribution
No credits recorded in the NVD database.
References
- https://supportcenter.devexpress.com/ticket/details/t394936/devexpress-security-advisory-updated-on-april-27-2023
- https://supportcenter.devexpress.com/ticket/details/t1159142/web-reporting-data-source-protection-bypassed-during-xml-deserialization
- https://code-white.com/public-vulnerability-list/
- https://supportcenter.devexpress.com/ticket/details/t1141947/data-source-protection-bypass-during-xml-deserialization
More from DevExpress
View All →CVE-2023-35817
DevExpress before 23.1.3 allows AsyncDownloader SSRF....
Medium
5
CVE-2023-35816
DevExpress before 23.1.3 allows arbitrary TypeConverter conversion....
Low
3.5
CVE-2023-35814
DevExpress before 23.1.3 does not properly protect XtraReport serialized data...
Low
3.5
CVE-2022-28684
This vulnerability allows remote attackers to execute arbitrary code on...
High
8.8
Affected Vendor
DevExpress
View all reports →Affected Software
DevExpress
Vulnerable Versions:
0, 22, 22.1.8, 22.2, 22.2.4, 23
Timeline
Official Publish:
April 28th, 2025
Last Modified:
April 28th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N