First published: Mon Jul 30 2018(Updated: )
In Lenovo xClarity Administrator versions earlier than 2.1.0, an authenticated LXCA user can, under specific circumstances, inject additional parameters into a specific web API call which can result in privileged command execution within LXCA's underlying operating system.
Credit: psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo XClarity Administrator | <2.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-9066 is a vulnerability in Lenovo xClarity Administrator versions earlier than 2.1.0 that allows an authenticated LXCA user to inject additional parameters into a specific web API call, leading to privileged command execution within LXCA's underlying operating system.
CVE-2018-9066 is categorized as critical with a severity score of 8.8.
The affected software is Lenovo xClarity Administrator versions earlier than 2.1.0.
An authenticated LXCA user can exploit CVE-2018-9066 by injecting additional parameters into a specific web API call.
Yes, Lenovo has released version 2.1.0 of xClarity Administrator which addresses this vulnerability. It is recommended to upgrade to this version.