CVE-2019-6187: Medium severity lenovo xclarity controller vulnerability
A stored CSV Injection vulnerability was reported in Lenovo XClarity Controller (XCC) that could allow an administrative or other appropriately permissioned user to store malformed data in certain XCC server informational fields, that could result in crafted formulas being stored in an exported CSV file. The crafted formula is not executed on XCC itself and has no effect on the server.
Affected Software
Remediation
Patch Available
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2019-6187?
The severity of CVE-2019-6187 is medium with a severity value of 6.5.
How does CVE-2019-6187 affect Lenovo XClarity Controller?
CVE-2019-6187 affects Lenovo XClarity Controller by allowing an administrative or other appropriately permissioned user to store malformed data in certain XCC server informational fields.
What is CSV Injection vulnerability?
CSV Injection vulnerability is a type of security vulnerability that occurs when untrusted input is inserted into a CSV (Comma-Separated Values) file, resulting in the execution of arbitrary commands or malicious code.
How can CVE-2019-6187 be fixed?
To fix CVE-2019-6187, users should apply the necessary security patches provided by Lenovo.
Where can I find more information about CVE-2019-6187?
More information about CVE-2019-6187 can be found on the Lenovo support website: https://support.lenovo.com/solutions/LEN-29118