CVE-2021-22298 Information

Description

There is a logic vulnerability in Huawei Gauss100 OLTP Product. An attacker with certain permissions could perform specific SQL statement to exploit this vulnerability. Due to insufficient security design successful exploit can cause service abnormal. Affected product versions include: ManageOne versions 6.5.1.1.B020 6.5.1.1.B030 6.5.1.1.B040 6.5.1.SPC100.B050 6.5.1.SPC101.B010 6.5.1.SPC101.B040 6.5.1.SPC200 6.5.1.SPC200.B010 6.5.1.SPC200.B030 6.5.1.SPC200.B040 6.5.1.SPC200.B050 6.5.1.SPC200.B060 6.5.1.SPC200.B070 6.5.1RC1.B070 6.5.1RC1.B080 6.5.1RC2.B040 6.5.1RC2.B050 6.5.1RC2.B060 6.5.1RC2.B070 6.5.1RC2.B080 6.5.1RC2.B090.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Reference

https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210113-01-gauss-en https://www.oracle.com/security-alerts/cpujan2022.html

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

NONE

Base Score

HIGH

Base Severity

6.5

Share on: