CVE-2023-34418: SQL Injection
A valid, authenticated LXCA user may be able to gain unauthorized access to events and other data stored in LXCA due to a SQL injection vulnerability in a specific web API.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
LXCAto a version that resolves this vulnerability.Fixed in 4.0
Event History
Frequently Asked Questions
What is CVE-2023-34418?
CVE-2023-34418 is a SQL injection vulnerability in a specific web API in Lenovo XClarity Administrator (LXCA) that allows a valid authenticated user to gain unauthorized access to events and other data stored in LXCA.
How does CVE-2023-34418 affect Lenovo XClarity Administrator?
CVE-2023-34418 affects Lenovo XClarity Administrator by allowing a valid authenticated user to gain unauthorized access to events and other data stored in LXCA.
What is the severity of CVE-2023-34418?
The severity of CVE-2023-34418 is high with a CVSS score of 8.1.
How can I fix CVE-2023-34418?
To fix CVE-2023-34418, users should apply the necessary security updates provided by Lenovo.
Where can I find more information about CVE-2023-34418?
More information about CVE-2023-34418 can be found on the Lenovo Product Security website.