PT-2021-19534 · Mcafee · Mcafee Database Security
Published
2021-06-03
·
Updated
2023-11-15
·
CVE-2021-31831
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
McAfee Database Security versions prior to 4.8.2
Description
The issue allows a remote authenticated attacker to gain access to signed SQL scripts that have been marked as deleted or expired within the administrative console. This access is only available through the REST API.
Recommendations
For versions prior to 4.8.2, update to version 4.8.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the REST API until the update is applied.
Fix
Files Accessible to External Parties
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mcafee Database Security