CVE-2018-9066: Input Validation
In Lenovo xClarity Administrator versions earlier than 2.1.0, an authenticated LXCA user can, under specific circumstances, inject additional parameters into a specific web API call which can result in privileged command execution within LXCA's underlying operating system.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-9066?
CVE-2018-9066 is a vulnerability in Lenovo xClarity Administrator versions earlier than 2.1.0 that allows an authenticated LXCA user to inject additional parameters into a specific web API call, leading to privileged command execution within LXCA's underlying operating system.
How severe is CVE-2018-9066?
CVE-2018-9066 is categorized as critical with a severity score of 8.8.
What is the affected software?
The affected software is Lenovo xClarity Administrator versions earlier than 2.1.0.
How can an authenticated LXCA user exploit this vulnerability?
An authenticated LXCA user can exploit CVE-2018-9066 by injecting additional parameters into a specific web API call.
Is there a fix for CVE-2018-9066?
Yes, Lenovo has released version 2.1.0 of xClarity Administrator which addresses this vulnerability. It is recommended to upgrade to this version.