First published: Wed Jun 02 2021(Updated: )
Cleartext Transmission of Sensitive Information vulnerability in the administrator interface of McAfee Database Security (DBSec) prior to 4.8.2 allows an administrator to view the unencrypted password of the McAfee Insights Server used to pass data to the Insights Server. This user is restricted to only have access to DBSec data in the Insights Server.
Credit: psirt@mcafee.com
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee Database Security | <4.8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-23896.
The severity of CVE-2021-23896 is medium with a severity value of 4.5.
McAfee Database Security (DBSec) prior to version 4.8.2 is affected by CVE-2021-23896.
An administrator can exploit this vulnerability to view the unencrypted password of the McAfee Insights Server used to pass data to the Insights Server.
Yes, a fix is available for CVE-2021-23896. It is recommended to update to McAfee Database Security version 4.8.2 or later.