Huawei ManageOne 6.5.0

CPE Details

Huawei ManageOne 6.5.0
6.5.0
2019-11-20
15h36 +00:00
2021-04-19
10h27 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:huawei:manageone:6.5.0:*:*:*:*:*:*:*

Informations

Vendor

huawei

Product

manageone

Version

6.5.0

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2021-22409 2021-05-20 17h13 +00:00 There is a denial of service vulnerability in some versions of ManageOne. There is a logic error in the implementation of a function of a module. When the service pressure is heavy, there is a low probability that an exception may occur. Successful exploit may cause some services abnormal.
5.3
Medium
CVE-2020-9115 2020-11-30 22h57 +00:00 ManageOne versions 6.5.1.1.B010, 6.5.1.1.B020, 6.5.1.1.B030, 6.5.1.1.B040, ,6.5.1.1.B050, 8.0.0 and 8.0.1 have a command injection vulnerability. An attacker with high privileges may exploit this vulnerability through some operations on the plug-in component. Due to insufficient input validation of some parameters, the attacker can exploit this vulnerability to inject commands to the target device.
7.2
High
CVE-2019-5289 2019-11-13 15h03 +00:00 Gauss100 OLTP database in ManageOne with versions of 6.5.0 have an out-of-bounds read vulnerability due to the insufficient checks of the specific packet length. Attackers can construct invalid packets to attack the active and standby communication channels. Successful exploit of this vulnerability could allow the attacker to crash the database on the standby node.
7.5
High
CVE-2019-14835 2019-09-17 13h09 +00:00 A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descriptors with invalid length to the host when migration is underway, could use this flaw to increase their privileges on the host.
7.8
High