Out-of-Bounds Read Vulnerability in Gauss100 OLTP Database by Huawei
CVE-2019-5289
7.5HIGH
Summary
The Gauss100 OLTP database, specifically version 6.5.0 from Huawei, is susceptible to an out-of-bounds read vulnerability caused by inadequate validation of packet lengths. This lack of proper checks allows attackers to send malformed packets, potentially affecting both active and standby communication channels. If exploited, the vulnerability could lead to a crash of the database on the standby node, compromising its reliability and availability.
Affected Version(s)
ManageOne 6.5.0
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved