CVE-2018-16093: LXCI for VMware
Published Nov 30, 2018
·Updated
In versions prior to 5.5, LXCI for VMware allows an authenticated user to write to any system file due to insufficient sanitization during the upload of a backup file.
Affected Software
1 affected component
Lenovo Xclarity Integrator Vcenter<5.5
Remediation
Patch Available
Information
Update LXCI for VMware to version 5.5 or higher.
Event History
Nov 30, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
RemedyDescriptionWeakness
Frequently Asked Questions
1
What is CVE-2018-16093?
CVE-2018-16093 is a vulnerability in LXCI for VMware versions prior to 5.5.
2
How does CVE-2018-16093 affect Lenovo Xclarity Integrator?
CVE-2018-16093 allows an authenticated user to write to any system file in Lenovo Xclarity Integrator vCenter versions prior to 5.5.
3
What is the severity of CVE-2018-16093?
CVE-2018-16093 has a severity rating of 6.5 (medium).
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2018-16093?
CVE-2018-16093 is associated with CWE-434.
5
How can I fix CVE-2018-16093?
To fix CVE-2018-16093, upgrade LXCI for VMware to version 5.5 or later.