PT-2019-18014 · Lenovo · Lenovo Xclarity Controller

Publicado

2019-11-20

·

Atualizado

2020-08-24

·

CVE-2019-6187

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Lenovo XClarity Controller (XCC) (affected versions not specified)
Description A stored CSV Injection issue was reported that could allow an administrative or other appropriately permissioned user to store malformed data in certain XCC server informational fields. This could result in crafted formulas being stored in an exported CSV file. The crafted formula has no effect on the XCC server itself.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-6187

Produtos afetados

Lenovo Xclarity Controller