CVE-2021-23895: Authorized deserialization of untrusted data in McAfee DBSec
Published Jun 2, 2021
·Updated
Deserialization of untrusted data vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows a remote authenticated attacker to create a reverse shell with administrator privileges on the DBSec server via carefully constructed Java serialized object sent to the DBSec server.
Affected Software
1 affected component
McAfee Database Security<4.8.2
Event History
Jun 2, 2021
CVE Published
via MITRE·01:05 PM
Data Sourced
via MITRE·01:05 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2021-23895.
2
What software is affected by this vulnerability?
McAfee Database Security (DBSec) prior to version 4.8.2 is affected.
3
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by sending a carefully constructed Java serialized object to the DBSec server.
4
What privileges can an attacker gain?
An attacker can gain administrator privileges on the DBSec server.
5
How severe is this vulnerability?
This vulnerability has a severity rating of 8.8 (critical).