Description
A stored CSV Injection vulnerability was reported in Lenovo XClarity Controller (XCC) that could allow an administrative or other appropriately permissioned user to store malformed data in certain XCC server informational fields, that could result in crafted formulas being stored in an exported CSV file. The crafted formula is not executed on XCC itself and has no effect on the server.
Published: 2019-11-20
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update LXCC to the version indicated for your product.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2019-15754 A stored CSV Injection vulnerability was reported in Lenovo XClarity Controller (XCC) that could allow an administrative or other appropriately permissioned user to store malformed data in certain XCC server informational fields, that could result in crafted formulas being stored in an exported CSV file. The crafted formula is not executed on XCC itself and has no effect on the server.
History

No history.

Subscriptions

Lenovo Thinksystem Sr670 Thinkagile 7d1h Thinkagile 7x82 Thinkagile 7x83 Thinkagile 7y11 Thinkagile 7y12 Thinkagile 7y13 Thinkagile 7y14 Thinkagile 7y88 Thinkagile 7y90 Thinkagile 7y92 Thinkagile 7y93 Thinkagile 7y94 Thinkagile 7z03 Thinkagile 7z04 Thinkagile 7z05 Thinkagile 7z06 Thinkagile 7z07 Thinkagile 7z20 Thinkagile Yx84 Thinksystem Sd530 Thinksystem Sd650 Thinksystem Sn550 Thinksystem Sn850 Thinksystem Sr150 Thinksystem Sr158 Thinksystem Sr250 Thinksystem Sr258 Thinksystem Sr530 Thinksystem Sr550 Thinksystem Sr570 Thinksystem Sr590 Thinksystem Sr630 Thinksystem Sr650 Thinksystem Sr850 Thinksystem Sr860 Thinksystem Sr950 Thinksystem St250 Thinksystem St258 Thinksystem St550 Thinksystem St558 Xclarity Controller
cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2024-09-17T00:50:51.427Z

Reserved: 2019-01-11T00:00:00.000Z

Link: CVE-2019-6187

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-11-20T02:15:10.787

Modified: 2024-11-21T04:46:07.577

Link: CVE-2019-6187

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses