Cleartext Transmission of Sensitive Information in McAfee DBSec
Vulnerability Description
Cleartext Transmission of Sensitive Information vulnerability in the administrator interface of McAfee Database Security (DBSec) prior to 4.8.2 allows an administrator to view the unencrypted password of the McAfee Insights Server used to pass data to the Insights Server. This user is restricted to only have access to DBSec data in the Insights Server.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-23896
Credits & Attribution
No credits recorded in the NVD database.
More from McAfee,LLC
View All →Affected Vendor
McAfee,LLC
View all reports →