CVE-2019-19757: XSS
An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered a Document Object Model (DOM) based cross-site scripting vulnerability in versions prior to 2.6.6 that could allow JavaScript code to be executed in the user's web browser if a specially crafted link is visited. The JavaScript code is executed on the user's system, not executed on LXCA itself.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2019-19757?
CVE-2019-19757 is a cross-site scripting vulnerability in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6.
What is the severity of CVE-2019-19757?
CVE-2019-19757 has a severity level of medium.
How does CVE-2019-19757 affect Lenovo XClarity Administrator?
CVE-2019-19757 allows JavaScript code execution in the user's web browser if a specially crafted link is visited in Lenovo XClarity Administrator versions prior to 2.6.6.
How can I fix CVE-2019-19757?
To fix CVE-2019-19757, update Lenovo XClarity Administrator to version 2.6.6 or later.
Where can I find more information about CVE-2019-19757?
More information about CVE-2019-19757 can be found at the Lenovo Product Security website: https://support.lenovo.com/us/en/product_security/LEN-29477