CVE-2021-22298
Last modified
CVE-2021-22298 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. There is a logic vulnerability in Huawei Gauss100 OLTP Product. An attacker with certain permissions could perform specific SQL statement to exploit this vulnerability. EPSS estimates a 0.91% chance of exploitation in the next 30 days.
Description
There is a logic vulnerability in Huawei Gauss100 OLTP Product. An attacker with certain permissions could perform specific SQL statement to exploit this vulnerability. Due to insufficient security design, successful exploit can cause service abnormal. Affected product versions include: ManageOne versions 6.5.1.1.B020, 6.5.1.1.B030, 6.5.1.1.B040, 6.5.1.SPC100.B050, 6.5.1.SPC101.B010, 6.5.1.SPC101.B040, 6.5.1.SPC200, 6.5.1.SPC200.B010, 6.5.1.SPC200.B030, 6.5.1.SPC200.B040, 6.5.1.SPC200.B050, 6.5.1.SPC200.B060, 6.5.1.SPC200.B070, 6.5.1RC1.B070, 6.5.1RC1.B080, 6.5.1RC2.B040, 6.5.1RC2.B050, 6.5.1RC2.B060, 6.5.1RC2.B070, 6.5.1RC2.B080, 6.5.1RC2.B090.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Huawei | Manageone | 6.5.1.1 | B020 |
| Huawei | Manageone | 8.0.0 | — |
References
- https://www.oracle.com/security-alerts/cpujan2022.htmlNot Applicable, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlNot Applicable, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-22298?
How severe is CVE-2021-22298?
How do I fix CVE-2021-22298?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-22291Improper Neutralization of Input During Web Page Generation …8.5
- CVE-2021-22292There is a denial of service (DoS) vulnerability in eCNS280 …7.5
- CVE-2021-22293Some Huawei products have an inconsistent interpretation of …7.5
- CVE-2021-22294A component API of the HarmonyOS 2.0 has a permission bypass…3.3
- CVE-2021-22295A component of the HarmonyOS has a permission bypass vulnera…5.5
- CVE-2021-22296A component of HarmonyOS 2.0 has a DoS vulnerability. Local …5.5
- CVE-2021-22299There is a local privilege escalation vulnerability in some …7.8
- CVE-2021-2230Vulnerability in the MySQL Server product of Oracle MySQL (c…4.9
- CVE-2021-22300There is an information leak vulnerability in eCNS280_TD ver…4.1
- CVE-2021-22301Mate 30 10.0.0.203(C00E201R7P2) have a buffer overflow vulne…6.7
- CVE-2021-22302There is an out-of-bound read vulnerability in Taurus-AL00A …7.1
- CVE-2021-22303There is a pointer double free vulnerability in Taurus-AL00A…3.3
Are you affected by CVE-2021-22298?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
