CVE-2019-5278

MEDIUM

Gauss100 OLTP <V100R019C00SPC200 - Info Disclosure

Title source: llm
STIX 2.1

Description

There is an out-of-bounds read vulnerability in the Advanced Packages feature of the Gauss100 OLTP database in CampusInsight before V100R019C00SPC200. Attackers who gain the specific permission can use this vulnerability by sending elaborate SQL statements to the database. Successful exploit of this vulnerability may cause the database to crash.

References (1)

Core 1

Scores

CVSS v3 6.5
EPSS 0.0023
EPSS Percentile 45.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-125
Status published
Products (1)
huawei/campusinsight v100r019c00
Published Dec 13, 2019
Tracked Since Feb 18, 2026