First published: Mon Mar 22 2021(Updated: )
There is an improper permission assignment vulnerability in Huawei ManageOne product. Due to improper security hardening, the process can run with a higher privilege. Successful exploit could allow certain users to do certain operations with improper permissions. Affected product versions include: ManageOne versions 8.0.0, 8.0.1.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei ManageOne | =8.0.0 | |
Huawei ManageOne | =8.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22311 is an improper permission assignment vulnerability in Huawei ManageOne product.
The severity of CVE-2021-22311 is high with a CVSS score of 7.2.
CVE-2021-22311 allows certain users to perform operations with improper permissions in Huawei ManageOne versions 8.0.0 and 8.0.1.
To fix the CVE-2021-22311 vulnerability, update Huawei ManageOne to a patched version as recommended by Huawei.
You can find more information about CVE-2021-22311 in the Huawei Security Advisory: https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210203-01-manageone-en