CVE-2018-9072: LXCI for VMware
In versions prior to 5.5, LXCI for VMware allows an authenticated user to download any system file due to insufficient input sanitization during file downloads.
Affected Software
Remediation
Patch Available
Information
Event History
Frequently Asked Questions
What is CVE-2018-9072?
CVE-2018-9072 is a vulnerability in Lenovo Xclarity Integrator where an authenticated user can download any system file due to insufficient input sanitization during file downloads.
How does CVE-2018-9072 impact Lenovo Xclarity Integrator?
CVE-2018-9072 allows an authenticated user to download any system file, potentially leading to unauthorized access or data exposure.
What is the severity level of CVE-2018-9072?
CVE-2018-9072 has a severity level of medium with a CVSS score of 6.5.
How can I fix CVE-2018-9072?
To fix CVE-2018-9072, it is recommended to update Lenovo Xclarity Integrator to version 5.5 or later, as this vulnerability has been fixed in subsequent releases.
Where can I find more information about CVE-2018-9072?
You can find more information about CVE-2018-9072, including technical details and remediation steps, in the Lenovo support article available at https://support.lenovo.com/us/en/solutions/LEN-23800.