CVE-2019-6187
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD
Description
A stored CSV Injection vulnerability was reported in Lenovo XClarity Controller (XCC) that could allow an administrative or other appropriately permissioned user to store malformed data in certain XCC server informational fields, that could result in crafted formulas being stored in an exported CSV file. The crafted formula is not executed on XCC itself and has no effect on the server.
Affected (4)
Products: Lenovo: Xclarity Controller
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before tei392m |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkagile 7x82 | All versions |
Lenovo Thinkagile 7y11 | All versions |
Lenovo Thinkagile 7y12 | All versions |
Lenovo Thinkagile 7y88 | All versions |
Lenovo Thinkagile 7y92 | All versions |
Lenovo Thinkagile 7z03 | All versions |
Lenovo Thinksystem Sd530 | All versions |
Lenovo Thinksystem Sd650 | All versions |
Lenovo Thinksystem Sn550 | All versions |
Lenovo Thinksystem Sn850 | All versions |
Lenovo Thinksystem Sr150 | All versions |
Lenovo Thinksystem Sr158 | All versions |
Lenovo Thinksystem Sr250 | All versions |
Lenovo Thinksystem Sr258 | All versions |
Lenovo Thinksystem Sr850 | All versions |
Lenovo Thinksystem Sr860 | All versions |
Lenovo Thinksystem St250 | All versions |
Lenovo Thinksystem St258 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before cdi340m |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinkagile 7d1h | All versions |
Lenovo Thinkagile 7x83 | All versions |
Lenovo Thinkagile 7y13 | All versions |
Lenovo Thinkagile 7y14 | All versions |
Lenovo Thinkagile 7y90 | All versions |
Lenovo Thinkagile 7y93 | All versions |
Lenovo Thinkagile 7y94 | All versions |
Lenovo Thinkagile 7z04 | All versions |
Lenovo Thinkagile 7z05 | All versions |
Lenovo Thinkagile 7z06 | All versions |
Lenovo Thinkagile 7z07 | All versions |
Lenovo Thinkagile 7z20 | All versions |
Lenovo Thinkagile Yx84 | All versions |
Lenovo Thinksystem Sr530 | All versions |
Lenovo Thinksystem Sr550 | All versions |
Lenovo Thinksystem Sr570 | All versions |
Lenovo Thinksystem Sr590 | All versions |
Lenovo Thinksystem Sr630 | All versions |
Lenovo Thinksystem Sr650 | All versions |
Lenovo Thinksystem St550 | All versions |
Lenovo Thinksystem St558 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before g1i312 |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinksystem Sr670 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before psi328m |
| Running on/with | Platform Versions |
|---|---|
Lenovo Thinksystem Sr950 | All versions |
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Timeline
No history available yet.