There is an improper permission assignment vulnerability in Huawei ManageOne product. Due to improper security hardening, the process can run with a higher privilege. Successful exploit could allow certain users to do certain operations with improper permissions. Affected product versions include: ManageOne versions 8.0.0, 8.0.1.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210203-01-manageone-en | vendor advisory |