Deserialization of untrusted data vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows a remote authenticated attacker to create a reverse shell with administrator privileges on the DBSec server via carefully constructed Java serialized object sent to the DBSec server.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-10821 Deserialization of untrusted data vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows a remote authenticated attacker to create a reverse shell with administrator privileges on the DBSec server via carefully constructed Java serialized object sent to the DBSec server.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: trellix

Published:

Updated: 2024-08-03T19:14:09.408Z

Reserved: 2021-01-12T00:00:00

Link: CVE-2021-23895

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-06-02T13:15:12.363

Modified: 2024-11-21T05:52:01.390

Link: CVE-2021-23895

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.