CVE-2018-16097: LXCI for VMware and LXCI for Microsoft System Center
Published Nov 30, 2018
·Updated
LXCI for VMware versions prior to 5.5 and LXCI for Microsoft System Center versions prior to 3.5, allow an authenticated user to write to any system file due to insufficient sanitization during the upload of a certificate.
Affected Software
2 affected components
Lenovo Xclarity Integrator Scvmm<3.5
Lenovo Xclarity Integrator Vcenter<5.5
Remediation
Patch Available
Information
Update LXCI for VMware to version 5.5 or higher.
Update LXCI for Microsoft System Center to version 3.5 or higher.
Event History
Nov 30, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
RemedyDescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2018-16097.
2
What is the severity level of CVE-2018-16097?
CVE-2018-16097 has a severity level of medium.
3
What is affected by CVE-2018-16097?
LXCI for VMware versions prior to 5.5 and LXCI for Microsoft System Center versions prior to 3.5 are affected by CVE-2018-16097.
4
How can an authenticated user exploit CVE-2018-16097?
An authenticated user can exploit CVE-2018-16097 by uploading a certificate without proper sanitization, allowing them to write to any system file.
5
Is there a fix available for CVE-2018-16097?
Yes, a fix for CVE-2018-16097 is available. Please refer to the official Lenovo support page for more information.