Unauthorized deserialization of untrusted data in McAfee DBSec
Vulnerability Description
Deserialization of untrusted data vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows a remote unauthenticated attacker to create a reverse shell with administrator privileges on the DBSec server via carefully constructed Java serialized object sent to the DBSec server.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-23894
Credits & Attribution
No credits recorded in the NVD database.
More from McAfee,LLC
View All →Affected Vendor
McAfee,LLC
View all reports →