Vulnerability Description
A stored CSV Injection vulnerability was reported in Lenovo XClarity Controller (XCC) that could allow an administrative or other appropriately permissioned user to store malformed data in certain XCC server informational fields, that could result in crafted formulas being stored in an exported CSV file. The crafted formula is not executed on XCC itself and has no effect on the server.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | Xclarity Controller | < tei392m |
| Lenovo | Thinkagile 7X82 | - |
| Lenovo | Thinkagile 7Y11 | - |
| Lenovo | Thinkagile 7Y12 | - |
| Lenovo | Thinkagile 7Y88 | - |
| Lenovo | Thinkagile 7Y92 | - |
| Lenovo | Thinkagile 7Z03 | - |
| Lenovo | Thinksystem Sd530 | - |
| Lenovo | Thinksystem Sd650 | - |
| Lenovo | Thinksystem Sn550 | - |
| Lenovo | Thinksystem Sn850 | - |
| Lenovo | Thinksystem Sr150 | - |
| Lenovo | Thinksystem Sr158 | - |
| Lenovo | Thinksystem Sr250 | - |
| Lenovo | Thinksystem Sr258 | - |
| Lenovo | Thinksystem Sr850 | - |
| Lenovo | Thinksystem Sr860 | - |
| Lenovo | Thinksystem St250 | - |
| Lenovo | Thinksystem St258 | - |
| Lenovo | Thinkagile 7D1H | - |
Related Weaknesses (CWE)
References
- https://support.lenovo.com/solutions/LEN-29118PatchVendor Advisory
- https://support.lenovo.com/solutions/LEN-29118PatchVendor Advisory
FAQ
What is CVE-2019-6187?
CVE-2019-6187 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A stored CSV Injection vulnerability was reported in Lenovo XClarity Controller (XCC) that could allow an administrative or other appropriately permissioned user to store malformed data in certain XCC...
How severe is CVE-2019-6187?
CVE-2019-6187 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-6187?
Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Xclarity Controller, Lenovo Thinkagile 7X82, Lenovo Thinkagile 7Y11, Lenovo Thinkagile 7Y12, Lenovo Thinkagile 7Y88.