First published: Thu May 20 2021(Updated: )
There is a denial of service vulnerability in some versions of ManageOne. In specific scenarios, due to the insufficient verification of the parameter, an attacker may craft some specific parameter. Successful exploit may cause some services abnormal.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei ManageOne | =6.5-rc2.b050 | |
Huawei ManageOne | =6.5.0 | |
Huawei ManageOne | =6.5.0-spc100.b210 | |
Huawei ManageOne | =6.5.0-spc100.b220 | |
Huawei ManageOne | =6.5.1-rc1.b060 | |
Huawei ManageOne | =6.5.1-rc1.b070 | |
Huawei ManageOne | =6.5.1-rc1.b080 | |
Huawei ManageOne | =6.5.1-rc2.b010 | |
Huawei ManageOne | =6.5.1-rc2.b020 | |
Huawei ManageOne | =6.5.1-rc2.b030 | |
Huawei ManageOne | =6.5.1-rc2.b040 | |
Huawei ManageOne | =6.5.1-rc2.b050 | |
Huawei ManageOne | =6.5.1-rc2.b060 | |
Huawei ManageOne | =6.5.1-rc2.b070 | |
Huawei ManageOne | =6.5.1-rc2.b080 | |
Huawei ManageOne | =6.5.1-rc2.b090 | |
Huawei ManageOne | =6.5.1-spc100.b050 | |
Huawei ManageOne | =6.5.1-spc101.b010 | |
Huawei ManageOne | =6.5.1-spc101.b040 | |
Huawei ManageOne | =6.5.1-spc200 | |
Huawei ManageOne | =6.5.1-spc200.b010 | |
Huawei ManageOne | =6.5.1-spc200.b030 | |
Huawei ManageOne | =6.5.1-spc200.b040 | |
Huawei ManageOne | =6.5.1-spc200.b050 | |
Huawei ManageOne | =6.5.1-spc200.b060 | |
Huawei ManageOne | =6.5.1-spc200.b070 | |
Huawei ManageOne | =6.5.1.1-b010 | |
Huawei ManageOne | =6.5.1.1-b020 | |
Huawei ManageOne | =6.5.1.1-b030 | |
Huawei ManageOne | =6.5.1.1-b040 | |
Huawei ManageOne | =8.0.0 | |
Huawei ManageOne | =8.0.0-lcnd81 | |
Huawei ManageOne | =8.0.0-rc2 | |
Huawei ManageOne | =8.0.0-rc3 | |
Huawei ManageOne | =8.0.0-rc3.b041 | |
Huawei ManageOne | =8.0.0-rc3.spc100 | |
Huawei ManageOne | =8.0.0-spc100 | |
Huawei ManageOne | =8.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22339 is a denial of service vulnerability in some versions of ManageOne.
CVE-2021-22339 has a severity rating of 6.5, which is considered medium.
The affected software versions of ManageOne include 6.5-rc2.b050, 6.5.0, 6.5.0-spc100.b210, 6.5.0-spc100.b220, 6.5.1-rc1.b060, 6.5.1-rc1.b070, 6.5.1-rc1.b080, 6.5.1-rc2.b010, 6.5.1-rc2.b020, 6.5.1-rc2.b030, 6.5.1-rc2.b040, 6.5.1-rc2.b050, 6.5.1-rc2.b060, 6.5.1-rc2.b070, 6.5.1-rc2.b080, 6.5.1-rc2.b090, 6.5.1-spc100.b050, 6.5.1-spc101.b010, 6.5.1-spc101.b040, 6.5.1-spc200, 6.5.1-spc200.b010, 6.5.1-spc200.b030, 6.5.1-spc200.b040, 6.5.1-spc200.b050, 6.5.1-spc200.b060, 6.5.1-spc200.b070, 6.5.1.1-b010, 6.5.1.1-b020, 6.5.1.1-b030, 6.5.1.1-b040, 8.0.0, 8.0.0-lcnd81, 8.0.0-rc2, 8.0.0-rc3, 8.0.0-rc3.b041, 8.0.0-rc3.spc100, 8.0.0-spc100, and 8.0.1.
An attacker can exploit CVE-2021-22339 by crafting specific parameters and sending them to the affected ManageOne service.
To fix CVE-2021-22339, it is recommended to upgrade to a patched version of ManageOne as provided by Huawei.