PT-2019-4348 · Microsoft+2 · System Center+4

CVE-2019-6179

·

Publicado

2019-09-03

·

Atualizado

2022-10-14

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Lenovo XClarity Administrator versions prior to 2.5.0 Lenovo XClarity Integrator (LXCI) for Microsoft System Center versions prior to 7.7.0 Lenovo XClarity Integrator (LXCI) for VMWare vCenter versions prior to 6.1.0
Description A vulnerability related to XML External Entity (XXE) processing was reported, which could allow information disclosure. The issue is associated with incorrect restriction of XML links to external objects, potentially enabling a remote attacker to disclose protected information.
Recommendations For Lenovo XClarity Administrator versions prior to 2.5.0, update to version 2.5.0 or later. For Lenovo XClarity Integrator (LXCI) for Microsoft System Center versions prior to 7.7.0, update to version 7.7.0 or later. For Lenovo XClarity Integrator (LXCI) for VMWare vCenter versions prior to 6.1.0, update to version 6.1.0 or later.

Correção

XXE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2020-00068
CVE-2019-6179

Produtos afetados

Lenovo Xclarity Administrator
Lenovo Xclarity Integrator (Lxci) For Microsoft System Center
Lenovo Xclarity Integrator (Lxci) For Vmware Vcenter
System Center
Vmware Vcenter