Vulnerability Description
Gauss100 OLTP database in ManageOne with versions of 6.5.0 have an out-of-bounds read vulnerability due to the insufficient checks of the specific packet length. Attackers can construct invalid packets to attack the active and standby communication channels. Successful exploit of this vulnerability could allow the attacker to crash the database on the standby node.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Manageone | 6.5.0 |
Related Weaknesses (CWE)
References
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190925-01-databasVendor Advisory
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190925-01-databasVendor Advisory
FAQ
What is CVE-2019-5289?
CVE-2019-5289 is a vulnerability with a CVSS score of 7.5 (HIGH). Gauss100 OLTP database in ManageOne with versions of 6.5.0 have an out-of-bounds read vulnerability due to the insufficient checks of the specific packet length. Attackers can construct invalid packet...
How severe is CVE-2019-5289?
CVE-2019-5289 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-5289?
Check the references section above for vendor advisories and patch information. Affected products include: Huawei Manageone.