Lenovo Xclarity Integrator vulnerabilities
4 known vulnerabilities affecting lenovo/xclarity_integrator.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2019-6179HIGHCVSS 7.5fixed in 6.1.0fixed in 7.7.02019-09-03
CVE-2019-6179 [HIGH] CWE-611 CVE-2019-6179: An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator
An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) prior to version 2.5.0 , Lenovo XClarity Integrator (LXCI) for Microsoft System Center prior to version 7.7.0, and Lenovo XClarity Integrator (LXCI) for VMWare vCenter prior to version 6.1.0 that could allow information disclosure.
nvd
CVE-2018-16093MEDIUMCVSS 6.5fixed in 5.52018-11-30
CVE-2018-16093 [MEDIUM] CWE-434 CVE-2018-16093: In versions prior to 5.5, LXCI for VMware allows an authenticated user to write to any system file d
In versions prior to 5.5, LXCI for VMware allows an authenticated user to write to any system file due to insufficient sanitization during the upload of a backup file.
nvd
CVE-2018-16097MEDIUMCVSS 6.5fixed in 3.5fixed in 5.52018-11-30
CVE-2018-16097 [MEDIUM] CWE-434 CVE-2018-16097: LXCI for VMware versions prior to 5.5 and LXCI for Microsoft System Center versions prior to 3.5, al
LXCI for VMware versions prior to 5.5 and LXCI for Microsoft System Center versions prior to 3.5, allow an authenticated user to write to any system file due to insufficient sanitization during the upload of a certificate.
nvd
CVE-2018-9072MEDIUMCVSS 6.5fixed in 5.52018-11-30
CVE-2018-9072 [MEDIUM] CWE-20 CVE-2018-9072: In versions prior to 5.5, LXCI for VMware allows an authenticated user to download any system file d
In versions prior to 5.5, LXCI for VMware allows an authenticated user to download any system file due to insufficient input sanitization during file downloads.
nvd