CVE-2018-16097
Summary
| CVE | CVE-2018-16097 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-11-30 14:29:00 UTC |
| Updated | 2018-12-28 17:36:00 UTC |
| Description | LXCI for VMware versions prior to 5.5 and LXCI for Microsoft System Center versions prior to 3.5, allow an authenticated user to write to any system file due to insufficient sanitization during the upload of a certificate. |
Risk And Classification
Problem Types: CWE-434
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Lenovo | Xclarity Integrator | All | All | All | All |
| Application | Lenovo | Xclarity Integrator | All | All | All | All |
| Application | Lenovo | Xclarity Integrator | All | All | All | All |
| Application | Lenovo | Xclarity Integrator | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Lenovo XClarity Integrator Vulnerabilities - Lenovo Support US | CONFIRM | support.lenovo.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.