← Back

CVE-2019-6187

nvd nist
Published: Nov 20, 2019Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

A stored CSV Injection vulnerability was reported in Lenovo XClarity Controller (XCC) that could allow an administrative or other appropriately permissioned user to store malformed data in certain XCC server informational fields, that could result in crafted formulas being stored in an exported CSV file. The crafted formula is not executed on XCC itself and has no effect on the server.

Affected (4)

1 product
Xclarity Controller
Configuration A
1 vulnerable · 18 platform
Vulnerable SoftwareAffected Versions
Before tei392m
Running on/withPlatform Versions
Lenovo
Thinkagile 7x82
All versions
Lenovo
Thinkagile 7y11
All versions
Lenovo
Thinkagile 7y12
All versions
Lenovo
Thinkagile 7y88
All versions
Lenovo
Thinkagile 7y92
All versions
Lenovo
Thinkagile 7z03
All versions
Lenovo
Thinksystem Sd530
All versions
Lenovo
Thinksystem Sd650
All versions
Lenovo
Thinksystem Sn550
All versions
Lenovo
Thinksystem Sn850
All versions
Lenovo
Thinksystem Sr150
All versions
Lenovo
Thinksystem Sr158
All versions
Lenovo
Thinksystem Sr250
All versions
Lenovo
Thinksystem Sr258
All versions
Lenovo
Thinksystem Sr850
All versions
Lenovo
Thinksystem Sr860
All versions
Lenovo
Thinksystem St250
All versions
Lenovo
Thinksystem St258
All versions
Configuration B
1 vulnerable · 21 platform
Vulnerable SoftwareAffected Versions
Before cdi340m
Running on/withPlatform Versions
Lenovo
Thinkagile 7d1h
All versions
Lenovo
Thinkagile 7x83
All versions
Lenovo
Thinkagile 7y13
All versions
Lenovo
Thinkagile 7y14
All versions
Lenovo
Thinkagile 7y90
All versions
Lenovo
Thinkagile 7y93
All versions
Lenovo
Thinkagile 7y94
All versions
Lenovo
Thinkagile 7z04
All versions
Lenovo
Thinkagile 7z05
All versions
Lenovo
Thinkagile 7z06
All versions
Lenovo
Thinkagile 7z07
All versions
Lenovo
Thinkagile 7z20
All versions
Lenovo
Thinkagile Yx84
All versions
Lenovo
Thinksystem Sr530
All versions
Lenovo
Thinksystem Sr550
All versions
Lenovo
Thinksystem Sr570
All versions
Lenovo
Thinksystem Sr590
All versions
Lenovo
Thinksystem Sr630
All versions
Lenovo
Thinksystem Sr650
All versions
Lenovo
Thinksystem St550
All versions
Lenovo
Thinksystem St558
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before g1i312
Running on/withPlatform Versions
Lenovo
Thinksystem Sr670
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before psi328m
Running on/withPlatform Versions
Lenovo
Thinksystem Sr950
All versions

References (2)

Source: psirt@lenovo.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.