CVE-2021-22298: Medium severity huawei manageone vulnerability
There is a logic vulnerability in Huawei Gauss100 OLTP Product. An attacker with certain permissions could perform specific SQL statement to exploit this vulnerability. Due to insufficient security design, successful exploit can cause service abnormal. Affected product versions include: ManageOne versions 6.5.1.1.B020, 6.5.1.1.B030, 6.5.1.1.B040, 6.5.1.SPC100.B050, 6.5.1.SPC101.B010, 6.5.1.SPC101.B040, 6.5.1.SPC200, 6.5.1.SPC200.B010, 6.5.1.SPC200.B030, 6.5.1.SPC200.B040, 6.5.1.SPC200.B050, 6.5.1.SPC200.B060, 6.5.1.SPC200.B070, 6.5.1RC1.B070, 6.5.1RC1.B080, 6.5.1RC2.B040, 6.5.1RC2.B050, 6.5.1RC2.B060, 6.5.1RC2.B070, 6.5.1RC2.B080, 6.5.1RC2.B090.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-22298?
CVE-2021-22298 is a logic vulnerability in the Huawei Gauss100 OLTP Product.
How does CVE-2021-22298 affect Huawei ManageOne?
CVE-2021-22298 affects certain versions of Huawei ManageOne, including 6.5.1.1-b020, 6.5.1.1-b030, 6.5.1.1-b040, and more.
What is the severity of CVE-2021-22298?
CVE-2021-22298 has a severity rating of 6.5 (medium).
How can an attacker exploit CVE-2021-22298?
An attacker with certain permissions can exploit CVE-2021-22298 by performing specific SQL statements.
How can I fix CVE-2021-22298?
To fix CVE-2021-22298, it is recommended to apply the necessary security patches provided by Huawei.