Huawei FusionAccess with software V100R005C10 and V100R005C20 could allow remote attackers with specific permission to inject a Lightweight Directory Access Protocol (LDAP) operation command into a specific input variable to obtain sensitive information from the database.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/94620 | vdb entry third party advisory |
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20161130-01-ldap-en | vendor advisory |