PT-2019-18014 · Lenovo · Lenovo Xclarity Controller

Published

2019-11-20

·

Updated

2020-08-24

·

CVE-2019-6187

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Lenovo XClarity Controller (XCC) (affected versions not specified)
Description A stored CSV Injection issue was reported that could allow an administrative or other appropriately permissioned user to store malformed data in certain XCC server informational fields. This could result in crafted formulas being stored in an exported CSV file. The crafted formula has no effect on the XCC server itself.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-6187

Affected Products

Lenovo Xclarity Controller