In System Management Module (SMM) versions prior to 1.06, the SMM web interface for changing Enclosure VPD fails to sufficiently sanitize all input for HTML tags, possibly opening a path for cross-site scripting.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Lenovo
Subscribe
|
System Management Module Firmware
Subscribe
Thinkagile Hx Enclosure 7x81
Subscribe
Thinkagile Hx Enclosure 7y87
Subscribe
Thinkagile Hx Enclosure 7z02
Subscribe
Thinkagile Vx Enclosure 7y11
Subscribe
Thinkagile Vx Enclosure 7y91
Subscribe
Thinksystem D2 Enclosure 7x20
Subscribe
Thinksystem Modular Enclosure 7x22
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-7953 | In System Management Module (SMM) versions prior to 1.06, the SMM web interface for changing Enclosure VPD fails to sufficiently sanitize all input for HTML tags, possibly opening a path for cross-site scripting. |
Fixes
Solution
Update SMM firmware
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://support.lenovo.com/us/en/solutions/LEN-24374 |
|
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2024-08-05T10:17:37.631Z
Reserved: 2018-08-29T00:00:00
Link: CVE-2018-16096
No data.
Status : Modified
Published: 2018-11-27T14:29:00.633
Modified: 2024-11-21T03:52:05.953
Link: CVE-2018-16096
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD