CVE-2016-6898

XML external entity (XXE) vulnerability in the Hyper Management Module (HMM) in Huawei E9000 rack servers with software before V100R001C00SPC296 allows remote authenticated users to read arbitrary files or cause a denial of service (web service outage) via a crafted XML document.
Configurations

Configuration 1 (hide)

cpe:2.3:a:huawei:e9000_chassis:*:*:*:*:*:*:*:*

History

21 Nov 2024, 02:57

Type Values Removed Values Added
References () http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160824-01-e9000-en - Vendor Advisory () http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160824-01-e9000-en - Vendor Advisory
References () http://www.securityfocus.com/bid/92620 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/92620 - Third Party Advisory, VDB Entry

Information

Published : 2016-09-07 19:28

Updated : 2024-11-21 02:57


NVD link : CVE-2016-6898

Mitre link : CVE-2016-6898

CVE.ORG link : CVE-2016-6898


JSON object : View

Products Affected

huawei

  • e9000_chassis
CWE
CWE-284

Improper Access Control