A stored CSV Injection vulnerability was reported in Lenovo XClarity Controller (XCC) that could allow an administrative or other appropriately permissioned user to store malformed data in certain XCC server informational fields, that could result in crafted formulas being stored in an exported CSV file. The crafted formula is not executed on XCC itself and has no effect on the server.

Project Subscriptions

Vendors Products
Thinksystem Sr670 Subscribe
Thinkagile 7d1h Subscribe
Thinkagile 7x82 Subscribe
Thinkagile 7x83 Subscribe
Thinkagile 7y11 Subscribe
Thinkagile 7y12 Subscribe
Thinkagile 7y13 Subscribe
Thinkagile 7y14 Subscribe
Thinkagile 7y88 Subscribe
Thinkagile 7y90 Subscribe
Thinkagile 7y92 Subscribe
Thinkagile 7y93 Subscribe
Thinkagile 7y94 Subscribe
Thinkagile 7z03 Subscribe
Thinkagile 7z04 Subscribe
Thinkagile 7z05 Subscribe
Thinkagile 7z06 Subscribe
Thinkagile 7z07 Subscribe
Thinkagile 7z20 Subscribe
Thinkagile Yx84 Subscribe
Thinksystem Sd530 Subscribe
Thinksystem Sd650 Subscribe
Thinksystem Sn550 Subscribe
Thinksystem Sn850 Subscribe
Thinksystem Sr150 Subscribe
Thinksystem Sr158 Subscribe
Thinksystem Sr250 Subscribe
Thinksystem Sr258 Subscribe
Thinksystem Sr530 Subscribe
Thinksystem Sr550 Subscribe
Thinksystem Sr570 Subscribe
Thinksystem Sr590 Subscribe
Thinksystem Sr630 Subscribe
Thinksystem Sr650 Subscribe
Thinksystem Sr850 Subscribe
Thinksystem Sr860 Subscribe
Thinksystem Sr950 Subscribe
Thinksystem St250 Subscribe
Thinksystem St258 Subscribe
Thinksystem St550 Subscribe
Thinksystem St558 Subscribe
Xclarity Controller Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2019-15754 A stored CSV Injection vulnerability was reported in Lenovo XClarity Controller (XCC) that could allow an administrative or other appropriately permissioned user to store malformed data in certain XCC server informational fields, that could result in crafted formulas being stored in an exported CSV file. The crafted formula is not executed on XCC itself and has no effect on the server.
Fixes

Solution

Update LXCC to the version indicated for your product.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2024-09-17T00:50:51.427Z

Reserved: 2019-01-11T00:00:00.000Z

Link: CVE-2019-6187

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-11-20T02:15:10.787

Modified: 2024-11-21T04:46:07.577

Link: CVE-2019-6187

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses