CVE-2021-37131
- EPSS 0.42%
- Veröffentlicht 27.10.2021 01:15:07
- Zuletzt bearbeitet 21.11.2024 06:14:42
There is a CSV injection vulnerability in ManageOne, iManager NetEco and iManager NetEco 6000. An attacker with high privilege may exploit this vulnerability through some operations to inject the CSV files. Due to insufficient input validation of som...
CVE-2021-22397
- EPSS 0.03%
- Veröffentlicht 02.08.2021 17:15:14
- Zuletzt bearbeitet 21.11.2024 05:50:02
There is a privilege escalation vulnerability in Huawei ManageOne 8.0.0. External parameters of some files are lack of verification when they are be called. Attackers can exploit this vulnerability by performing these files to cause privilege escalat...
CVE-2021-22340
- EPSS 0.02%
- Veröffentlicht 29.06.2021 19:15:09
- Zuletzt bearbeitet 21.11.2024 05:49:56
There is a multiple threads race condition vulnerability in Huawei product. A race condition exists for concurrent I/O read by multiple threads. An attacker with the root permission can exploit this vulnerability by performing some operations. Succes...
CVE-2021-22339
- EPSS 0.07%
- Veröffentlicht 20.05.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 05:49:56
There is a denial of service vulnerability in some versions of ManageOne. In specific scenarios, due to the insufficient verification of the parameter, an attacker may craft some specific parameter. Successful exploit may cause some services abnormal...
CVE-2021-22409
- EPSS 0.17%
- Veröffentlicht 20.05.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 05:50:04
There is a denial of service vulnerability in some versions of ManageOne. There is a logic error in the implementation of a function of a module. When the service pressure is heavy, there is a low probability that an exception may occur. Successful e...
CVE-2021-22314
- EPSS 0.02%
- Veröffentlicht 22.03.2021 20:15:17
- Zuletzt bearbeitet 21.11.2024 05:49:53
There is a local privilege escalation vulnerability in some versions of ManageOne. A local authenticated attacker could perform specific operations to exploit this vulnerability. Successful exploitation may cause the attacker to obtain a higher privi...
CVE-2021-22311
- EPSS 0.15%
- Veröffentlicht 22.03.2021 19:15:11
- Zuletzt bearbeitet 21.11.2024 05:49:53
There is an improper permission assignment vulnerability in Huawei ManageOne product. Due to improper security hardening, the process can run with a higher privilege. Successful exploit could allow certain users to do certain operations with improper...
CVE-2021-22293
- EPSS 0.13%
- Veröffentlicht 06.02.2021 03:15:12
- Zuletzt bearbeitet 21.11.2024 05:49:51
Some Huawei products have an inconsistent interpretation of HTTP requests vulnerability. Attackers can exploit this vulnerability to cause information leak. Affected product versions include: CampusInsight versions V100R019C10; ManageOne versions 6.5...
CVE-2020-9205
- EPSS 0.13%
- Veröffentlicht 06.02.2021 02:15:12
- Zuletzt bearbeitet 21.11.2024 05:40:09
There has a CSV injection vulnerability in ManageOne 8.0.1. An attacker with common privilege may exploit this vulnerability through some operations to inject the CSV files. Due to insufficient input validation of some parameters, the attacker can ex...
CVE-2021-22298
- EPSS 0.19%
- Veröffentlicht 06.02.2021 02:15:12
- Zuletzt bearbeitet 21.11.2024 05:49:51
There is a logic vulnerability in Huawei Gauss100 OLTP Product. An attacker with certain permissions could perform specific SQL statement to exploit this vulnerability. Due to insufficient security design, successful exploit can cause service abnorma...