Critical severity9.6NVD Advisory· Published Jun 2, 2021· Updated Jun 17, 2026
CVE-2021-23894
CVE-2021-23894
Description
Deserialization of untrusted data vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows a remote unauthenticated attacker to create a reverse shell with administrator privileges on the DBSec server via carefully constructed Java serialized object sent to the DBSec server.
Affected products
3cpe:2.3:a:mcafee:database_security:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:mcafee:database_security:*:*:*:*:*:*:*:*range: <4.8.2
- (no CPE)range: <4.8.2
- Range: unspecified
Patches
Vulnerability mechanics
References
1- kc.mcafee.com/corporate/indexnvdBroken Link
News mentions
0No linked articles in our index yet.