CVE-2021-31831: fallo de gravedad media en McAfee Database Security (DBSec)
Incorrect access to deleted scripts vulnerability in McAfee DBSec
Publicada el · Actualizada el
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 4.9epss 0.6%
probabilidad de explotación
0.6%top 51% de las CVE
explotación observada
noninguna fuente lo reporta
Incorrect access to deleted scripts vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows a remote authenticated attacker to gain access to signed SQL scripts which have been marked as deleted or expired within the administrative console. This access was only available through the REST API.
CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Productos afectados
McAfee,LLC · McAfee Database Security (DBSec)CVEs relacionadas — McAfee Database Security (DBSec)
En el mismo producto, de las más peligrosas a las menos.
CVE-2021-23894CRITICALUnauthorized deserialization of untrusted data in McAfee DBSecEPSS 2.2%CVE-2021-23895CRITICALAuthorized deserialization of untrusted data in McAfee DBSecEPSS 1.9%CVE-2021-31850MEDIUMDenial of Service in Database Security on WindowsEPSS 1.0%CVE-2021-31830MEDIUMCross site Scripting (XSS) vulnerability in McAfee DBSecEPSS 0.5%CVE-2021-23896LOWCleartext Transmission of Sensitive Information in McAfee DBSecEPSS 0.2%