CVE-2015-2253: Infoleak
Published Jun 8, 2017
·Updated
The XML interface in Huawei OceanStor UDS devices with software before V100R002C01SPC102 allows remote authenticated users to obtain sensitive information via a crafted XML document.
Affected Software
2 affected components
Huawei Oceanstor Uds Firmware<=v100r002c01spc101
Huawei OceanStor UDS
Event History
Jun 8, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-2253?
CVE-2015-2253 is rated as a medium severity vulnerability due to its potential for sensitive information exposure.
2
How do I fix CVE-2015-2253?
To fix CVE-2015-2253, upgrade the Huawei OceanStor UDS devices to software version V100R002C01SPC102 or later.
3
Who is affected by CVE-2015-2253?
CVE-2015-2253 affects Huawei OceanStor UDS devices running software versions prior to V100R002C01SPC102.
4
What type of attacks can exploit CVE-2015-2253?
CVE-2015-2253 can be exploited by remote authenticated users to access sensitive information through crafted XML documents.
5
Is there a workaround for CVE-2015-2253?
There are no documented workarounds for CVE-2015-2253, so the recommended action is to update the software.