PT-2018-18827 · Lenovo · Lenovo Xclarity Administrator

Publicado

2018-07-30

·

Atualizado

2019-10-03

·

CVE-2018-9066

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Lenovo xClarity Administrator versions prior to 2.1.0
Description The issue allows an authenticated LXCA user to inject additional parameters into a specific web API call, resulting in privileged command execution within LXCA's underlying operating system.
Recommendations For versions prior to 2.1.0, update to version 2.1.0 or later to resolve the issue.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-9066

Produtos afetados

Lenovo Xclarity Administrator