First published: Fri Nov 30 2018(Updated: )
LXCI for VMware versions prior to 5.5 and LXCI for Microsoft System Center versions prior to 3.5, allow an authenticated user to write to any system file due to insufficient sanitization during the upload of a certificate.
Credit: psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo Xclarity Integrator | <3.5 | |
Lenovo Xclarity Integrator | <5.5 |
Update LXCI for VMware to version 5.5 or higher. Update LXCI for Microsoft System Center to version 3.5 or higher.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2018-16097.
CVE-2018-16097 has a severity level of medium.
LXCI for VMware versions prior to 5.5 and LXCI for Microsoft System Center versions prior to 3.5 are affected by CVE-2018-16097.
An authenticated user can exploit CVE-2018-16097 by uploading a certificate without proper sanitization, allowing them to write to any system file.
Yes, a fix for CVE-2018-16097 is available. Please refer to the official Lenovo support page for more information.