First published: Wed Jun 02 2021(Updated: )
Deserialization of untrusted data vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows a remote authenticated attacker to create a reverse shell with administrator privileges on the DBSec server via carefully constructed Java serialized object sent to the DBSec server.
Credit: psirt@mcafee.com trellixpsirt@trellix.com
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee Database Security | <4.8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-23895.
McAfee Database Security (DBSec) prior to version 4.8.2 is affected.
An attacker can exploit this vulnerability by sending a carefully constructed Java serialized object to the DBSec server.
An attacker can gain administrator privileges on the DBSec server.
This vulnerability has a severity rating of 8.8 (critical).