ManageOne versions 6.5.1.1.B010, 6.5.1.1.B020, 6.5.1.1.B030, 6.5.1.1.B040, ,6.5.1.1.B050, 8.0.0 and 8.0.1 have a command injection vulnerability. An attacker with high privileges may exploit this vulnerability through some operations on the plug-in component. Due to insufficient input validation of some parameters, the attacker can exploit this vulnerability to inject commands to the target device.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-29944 ManageOne versions 6.5.1.1.B010, 6.5.1.1.B020, 6.5.1.1.B030, 6.5.1.1.B040, ,6.5.1.1.B050, 8.0.0 and 8.0.1 have a command injection vulnerability. An attacker with high privileges may exploit this vulnerability through some operations on the plug-in component. Due to insufficient input validation of some parameters, the attacker can exploit this vulnerability to inject commands to the target device.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: huawei

Published:

Updated: 2024-08-04T10:19:19.919Z

Reserved: 2020-02-18T00:00:00

Link: CVE-2020-9115

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-12-01T00:15:11.320

Modified: 2024-11-21T05:40:04.293

Link: CVE-2020-9115

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.