PT-2021-19549 · Unknown · Database Security

Ikth

+1

·

Published

2021-12-08

·

Updated

2022-04-06

·

CVE-2021-31850

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Database Security versions prior to 4.8.4
Description: A denial-of-service issue allows a remote authenticated administrator to trigger a denial-of-service attack against the Database Security server. The configuration of Archiving through the User interface incorrectly allowed the creation of directories and files in Windows system directories and other locations where sensitive data could be overwritten, potentially leading to data destruction on the server.
Recommendations: For versions prior to 4.8.4, update to version 4.8.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the Archiving feature through the User interface to minimize the risk of exploitation. Additionally, restrict the creation of directories and files in sensitive locations to prevent potential data destruction.

Fix

Files Accessible to External Parties

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-31850
ZDI-21-1535

Affected Products

Database Security