CVE-2019-6187
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/11/2019
Last modified:
24/08/2020
Description
A stored CSV Injection vulnerability was reported in Lenovo XClarity Controller (XCC) that could allow an administrative or other appropriately permissioned user to store malformed data in certain XCC server informational fields, that could result in crafted formulas being stored in an exported CSV file. The crafted formula is not executed on XCC itself and has no effect on the server.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Base Score 2.0
4.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:lenovo:xclarity_controller:*:*:*:*:*:*:*:* | tei392m (excluding) | |
| cpe:2.3:h:lenovo:thinkagile_7x82:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:lenovo:thinkagile_7y11:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:lenovo:thinkagile_7y12:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:lenovo:thinkagile_7y88:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:lenovo:thinkagile_7y92:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:lenovo:thinkagile_7z03:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:lenovo:thinksystem_sd530:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:lenovo:thinksystem_sd650:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:lenovo:thinksystem_sn550:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:lenovo:thinksystem_sn850:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:lenovo:thinksystem_sr150:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:lenovo:thinksystem_sr158:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:lenovo:thinksystem_sr250:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:lenovo:thinksystem_sr258:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



