Out-of-Bounds Read Vulnerability in Gauss100 OLTP Database by Huawei
CVE-2019-5289

7.5HIGH

Key Information:

Vendor
Huawei
Status
Vendor
CVE Published:
13 November 2019

Summary

The Gauss100 OLTP database, specifically version 6.5.0 from Huawei, is susceptible to an out-of-bounds read vulnerability caused by inadequate validation of packet lengths. This lack of proper checks allows attackers to send malformed packets, potentially affecting both active and standby communication channels. If exploited, the vulnerability could lead to a crash of the database on the standby node, compromising its reliability and availability.

Affected Version(s)

ManageOne 6.5.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.