CVE-2021-23894

CRITICAL

McAfee Database Security < 4.8.2 - Unauthenticated Remote Code Execution via Java Deserialization

Title source: llm
STIX 2.1

Description

Deserialization of untrusted data vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows a remote unauthenticated attacker to create a reverse shell with administrator privileges on the DBSec server via carefully constructed Java serialized object sent to the DBSec server.

References (1)

Core 1
Core References

Scores

CVSS v3 9.6
EPSS 0.0428
EPSS Percentile 89.0%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-502
Status published
Products (1)
mcafee/database_security < 4.8.2
Published Jun 02, 2021
Tracked Since Feb 18, 2026