PT-2023-29831 · Lenovo · Thinksystem

Published

2023-10-24

·

Updated

2023-11-07

·

CVE-2023-4608

CVSS v3.1

4.1

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions ThinkSystem versions v2 and v3
Description An authenticated XCC user with elevated privileges can perform blind SQL injection in limited cases through a crafted API command.
Recommendations For ThinkSystem versions v2 and v3, consider restricting access to the API until a patch is available. As a temporary workaround, limit the privileges of XCC users to minimize the risk of exploitation.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2023-4608

Affected Products

Thinksystem