Vulnerability Description
LXCI for VMware versions prior to 5.5 and LXCI for Microsoft System Center versions prior to 3.5, allow an authenticated user to write to any system file due to insufficient sanitization during the upload of a certificate.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | Xclarity Integrator | < 3.5 |
Related Weaknesses (CWE)
References
- https://support.lenovo.com/us/en/solutions/LEN-23800PatchVendor Advisory
- https://support.lenovo.com/us/en/solutions/LEN-23800PatchVendor Advisory
FAQ
What is CVE-2018-16097?
CVE-2018-16097 is a vulnerability with a CVSS score of 6.5 (MEDIUM). LXCI for VMware versions prior to 5.5 and LXCI for Microsoft System Center versions prior to 3.5, allow an authenticated user to write to any system file due to insufficient sanitization during the up...
How severe is CVE-2018-16097?
CVE-2018-16097 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-16097?
Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Xclarity Integrator.