Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-31850

Опубликовано: 08 дек. 2021
Источник: nvd
CVSS3: 6.1
CVSS2: 4.9
EPSS Низкий

Описание

A denial-of-service vulnerability in Database Security (DBS) prior to 4.8.4 allows a remote authenticated administrator to trigger a denial-of-service attack against the DBS server. The configuration of Archiving through the User interface incorrectly allowed the creation of directories and files in Windows system directories and other locations where sensitive data could be overwritten. The former could lead to a DoS, whilst the latter could lead to data destruction on the DBS server.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:mcafee:database_security:*:*:*:*:*:*:*:*
Версия до 4.8.4 (исключая)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

EPSS

Процентиль: 52%
0.00285
Низкий

6.1 Medium

CVSS3

4.9 Medium

CVSS2

Дефекты

CWE-552
CWE-552

Связанные уязвимости

CVSS3: 6.1
github
около 4 лет назад

A denial-of-service vulnerability in Database Security (DBS) prior to 4.8.4 allows a remote authenticated administrator to trigger a denial-of-service attack against the DBS server. The configuration of Archiving through the User interface incorrectly allowed the creation of directories and files in Windows system directories and other locations where sensitive data could be overwritten. The former could lead to a DoS, whilst the latter could lead to data destruction on the DBS server.

EPSS

Процентиль: 52%
0.00285
Низкий

6.1 Medium

CVSS3

4.9 Medium

CVSS2

Дефекты

CWE-552
CWE-552