CVE-2021-23896: fallo de gravedad baja en McAfee Database Security (DBSec)
Cleartext Transmission of Sensitive Information in McAfee DBSec
Publicada el · Actualizada el
8Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 3.2epss 0.2%
probabilidad de explotación
0.2%top 90% de las CVE
explotación observada
noninguna fuente lo reporta
Cleartext Transmission of Sensitive Information vulnerability in the administrator interface of McAfee Database Security (DBSec) prior to 4.8.2 allows an administrator to view the unencrypted password of the McAfee Insights Server used to pass data to the Insights Server. This user is restricted to only have access to DBSec data in the Insights Server.
CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N
Productos afectados
McAfee,LLC · McAfee Database Security (DBSec)CVEs relacionadas — McAfee Database Security (DBSec)
En el mismo producto, de las más peligrosas a las menos.
CVE-2021-23894CRITICALUnauthorized deserialization of untrusted data in McAfee DBSecEPSS 2.2%CVE-2021-23895CRITICALAuthorized deserialization of untrusted data in McAfee DBSecEPSS 1.9%CVE-2021-31850MEDIUMDenial of Service in Database Security on WindowsEPSS 1.0%CVE-2021-31831MEDIUMIncorrect access to deleted scripts vulnerability in McAfee DBSecEPSS 0.6%CVE-2021-31830MEDIUMCross site Scripting (XSS) vulnerability in McAfee DBSecEPSS 0.5%