Skip to main content

Vendor/product archive

huawei / manageone CVEs

Beta · best-effort

14 CVEs tagged to huawei / manageone0 Critical, 6 High, 7 Medium, 1 Low, 0 Unrated.

CVE-2021-22397

Published Aug 2, 2021

There is a privilege escalation vulnerability in Huawei ManageOne 8.0.0. External parameters of some files are lack of verification when they are be called. Attackers can exploit…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22340

Published Jun 29, 2021

There is a multiple threads race condition vulnerability in Huawei product. A race condition exists for concurrent I/O read by multiple threads. An attacker with the root permissi…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22409

Published May 20, 2021

There is a denial of service vulnerability in some versions of ManageOne. There is a logic error in the implementation of a function of a module. When the service pressure is heav…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22339

Published May 20, 2021

There is a denial of service vulnerability in some versions of ManageOne. In specific scenarios, due to the insufficient verification of the parameter, an attacker may craft some…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22314

Published Mar 22, 2021

There is a local privilege escalation vulnerability in some versions of ManageOne. A local authenticated attacker could perform specific operations to exploit this vulnerability.…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-22311

Published Mar 22, 2021

There is an improper permission assignment vulnerability in Huawei ManageOne product. Due to improper security hardening, the process can run with a higher privilege. Successful e…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-22298

Published Feb 6, 2021

There is a logic vulnerability in Huawei Gauss100 OLTP Product. An attacker with certain permissions could perform specific SQL statement to exploit this vulnerability. Due to ins…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-9205

Published Feb 6, 2021

There has a CSV injection vulnerability in ManageOne 8.0.1. An attacker with common privilege may exploit this vulnerability through some operations to inject the CSV files. Due t…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-9115

Published Dec 1, 2020

ManageOne versions 6.5.1.1.B010, 6.5.1.1.B020, 6.5.1.1.B030, 6.5.1.1.B040, ,6.5.1.1.B050, 8.0.0 and 8.0.1 have a command injection vulnerability. An attacker with high privileges…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-1862

Published Mar 20, 2020

There is a double free vulnerability in some Huawei products. A local attacker with low privilege may perform some operations to exploit the vulnerability. Due to doubly freeing m…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2019-5289

Published Nov 13, 2019

Gauss100 OLTP database in ManageOne with versions of 6.5.0 have an out-of-bounds read vulnerability due to the insufficient checks of the specific packet length. Attackers can con…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-14 of 14 CVEsPage 1 of 1