First published: Fri Feb 14 2020(Updated: )
An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered a Document Object Model (DOM) based cross-site scripting vulnerability in versions prior to 2.6.6 that could allow JavaScript code to be executed in the user's web browser if a specially crafted link is visited. The JavaScript code is executed on the user's system, not executed on LXCA itself.
Credit: psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo XClarity Administrator | <2.6.6 |
Update your LXCA installation to version 2.6.6 or later. Installation note: You will need to update to LXCA 2.6.0 before installing the latest fix bundle (v 2.6.6).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-19757 is a cross-site scripting vulnerability in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6.
CVE-2019-19757 has a severity level of medium.
CVE-2019-19757 allows JavaScript code execution in the user's web browser if a specially crafted link is visited in Lenovo XClarity Administrator versions prior to 2.6.6.
To fix CVE-2019-19757, update Lenovo XClarity Administrator to version 2.6.6 or later.
More information about CVE-2019-19757 can be found at the Lenovo Product Security website: https://support.lenovo.com/us/en/product_security/LEN-29477