CVE-2021-31831

Incorrect access to deleted scripts vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows a remote authenticated attacker to gain access to signed SQL scripts which have been marked as deleted or expired within the administrative console. This access was only available through the REST API.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mcafee:database_security:*:*:*:*:*:*:*:*

History

15 Nov 2023, 18:53

Type Values Removed Values Added
References () https://kc.mcafee.com/corporate/index?page=content&id=SB10359 - () https://kc.mcafee.com/corporate/index?page=content&id=SB10359 - Broken Link
CWE CWE-552
CVSS v2 : 6.5
v3 : 8.8
v2 : 6.5
v3 : 5.5

07 Nov 2023, 03:35

Type Values Removed Values Added
References (CONFIRM) https://kc.mcafee.com/corporate/index?page=content&id=SB10359 - Vendor Advisory () https://kc.mcafee.com/corporate/index?page=content&id=SB10359 -
CWE CWE-552

15 Jun 2021, 13:35

Type Values Removed Values Added
References (CONFIRM) https://kc.mcafee.com/corporate/index?page=content&id=SB10359 - (CONFIRM) https://kc.mcafee.com/corporate/index?page=content&id=SB10359 - Vendor Advisory
CPE cpe:2.3:a:mcafee:database_security:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 6.5
v3 : 8.8
CWE CWE-552

03 Jun 2021, 11:32

Type Values Removed Values Added
New CVE

Information

Published : 2021-06-03 10:15

Updated : 2023-12-10 13:55


NVD link : CVE-2021-31831

Mitre link : CVE-2021-31831

CVE.ORG link : CVE-2021-31831


JSON object : View

Products Affected

mcafee

  • database_security
CWE
CWE-552

Files or Directories Accessible to External Parties