The DeviceManager in Huawei OceanStor UDS devices with software before V100R002C01SPC102 might allow remote attackers to obtain sensitive information via a crafted UDS patch with JavaScript.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2251
Reference (s):
- http://www1.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-417837.htm