CVE-2021-23896: Cleartext Transmission of Sensitive Information in McAfee DBSec
Cleartext Transmission of Sensitive Information vulnerability in the administrator interface of McAfee Database Security (DBSec) prior to 4.8.2 allows an administrator to view the unencrypted password of the McAfee Insights Server used to pass data to the Insights Server. This user is restricted to only have access to DBSec data in the Insights Server.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2021-23896.
What is the severity of CVE-2021-23896?
The severity of CVE-2021-23896 is medium with a severity value of 4.5.
What software is affected by CVE-2021-23896?
McAfee Database Security (DBSec) prior to version 4.8.2 is affected by CVE-2021-23896.
How can an administrator exploit this vulnerability?
An administrator can exploit this vulnerability to view the unencrypted password of the McAfee Insights Server used to pass data to the Insights Server.
Is there a fix available for CVE-2021-23896?
Yes, a fix is available for CVE-2021-23896. It is recommended to update to McAfee Database Security version 4.8.2 or later.