Vulnerability Details CVE-2021-23895
Deserialization of untrusted data vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows a remote authenticated attacker to create a reverse shell with administrator privileges on the DBSec server via carefully constructed Java serialized object sent to the DBSec server.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.014
EPSS Ranking 79.7%
CVSS Severity
CVSS v3 Score 9.0
CVSS v2 Score 9.0
Products affected by CVE-2021-23895
-
cpe:2.3:a:mcafee:database_security:-
-
cpe:2.3:a:mcafee:database_security:4.6.6
-
cpe:2.3:a:mcafee:database_security:4.8.0