A stored CSV Injection vulnerability was reported in Lenovo XClarity Controller (XCC) that could allow an administrative or other appropriately permissioned user to store malformed data in certain XCC server informational fields, that could result in crafted formulas being stored in an exported CSV file. The crafted formula is not executed on XCC itself and has no effect on the server.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Lenovo
Subscribe
|
Thinksystem Sr670
Subscribe
Thinkagile 7d1h
Subscribe
Thinkagile 7x82
Subscribe
Thinkagile 7x83
Subscribe
Thinkagile 7y11
Subscribe
Thinkagile 7y12
Subscribe
Thinkagile 7y13
Subscribe
Thinkagile 7y14
Subscribe
Thinkagile 7y88
Subscribe
Thinkagile 7y90
Subscribe
Thinkagile 7y92
Subscribe
Thinkagile 7y93
Subscribe
Thinkagile 7y94
Subscribe
Thinkagile 7z03
Subscribe
Thinkagile 7z04
Subscribe
Thinkagile 7z05
Subscribe
Thinkagile 7z06
Subscribe
Thinkagile 7z07
Subscribe
Thinkagile 7z20
Subscribe
Thinkagile Yx84
Subscribe
Thinksystem Sd530
Subscribe
Thinksystem Sd650
Subscribe
Thinksystem Sn550
Subscribe
Thinksystem Sn850
Subscribe
Thinksystem Sr150
Subscribe
Thinksystem Sr158
Subscribe
Thinksystem Sr250
Subscribe
Thinksystem Sr258
Subscribe
Thinksystem Sr530
Subscribe
Thinksystem Sr550
Subscribe
Thinksystem Sr570
Subscribe
Thinksystem Sr590
Subscribe
Thinksystem Sr630
Subscribe
Thinksystem Sr650
Subscribe
Thinksystem Sr850
Subscribe
Thinksystem Sr860
Subscribe
Thinksystem Sr950
Subscribe
Thinksystem St250
Subscribe
Thinksystem St258
Subscribe
Thinksystem St550
Subscribe
Thinksystem St558
Subscribe
Xclarity Controller
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-15754 | A stored CSV Injection vulnerability was reported in Lenovo XClarity Controller (XCC) that could allow an administrative or other appropriately permissioned user to store malformed data in certain XCC server informational fields, that could result in crafted formulas being stored in an exported CSV file. The crafted formula is not executed on XCC itself and has no effect on the server. |
Fixes
Solution
Update LXCC to the version indicated for your product.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://support.lenovo.com/solutions/LEN-29118 |
|
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2024-09-17T00:50:51.427Z
Reserved: 2019-01-11T00:00:00
Link: CVE-2019-6187
No data.
Status : Modified
Published: 2019-11-20T02:15:10.787
Modified: 2024-11-21T04:46:07.577
Link: CVE-2019-6187
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD