CVE-2021-23894

CRITICAL

Mcafee Database Security < 4.8.2 - Insecure Deserialization

Title source: rule

Description

Deserialization of untrusted data vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows a remote unauthenticated attacker to create a reverse shell with administrator privileges on the DBSec server via carefully constructed Java serialized object sent to the DBSec server.

Scores

CVSS v3 9.6
EPSS 0.0428
EPSS Percentile 88.7%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Classification

CWE
CWE-502
Status published

Affected Products (1)

mcafee/database_security < 4.8.2

Timeline

Published Jun 02, 2021
Tracked Since Feb 18, 2026