CVE-2019-6187
Summary
| CVE | CVE-2019-6187 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-11-20 02:15:00 UTC |
| Updated | 2020-08-24 17:37:00 UTC |
| Description | A stored CSV Injection vulnerability was reported in Lenovo XClarity Controller (XCC) that could allow an administrative or other appropriately permissioned user to store malformed data in certain XCC server informational fields, that could result in crafted formulas being stored in an exported CSV file. The crafted formula is not executed on XCC itself and has no effect on the server. |
Risk And Classification
Problem Types: CWE-1236
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Lenovo | Thinkagile 7d1h | - | All | All | All |
| Hardware | Lenovo | Thinkagile 7d1h | - | All | All | All |
| Hardware | Lenovo | Thinkagile 7x82 | - | All | All | All |
| Hardware | Lenovo | Thinkagile 7x82 | - | All | All | All |
| Hardware | Lenovo | Thinkagile 7x83 | - | All | All | All |
| Hardware | Lenovo | Thinkagile 7x83 | - | All | All | All |
| Hardware | Lenovo | Thinkagile 7y11 | - | All | All | All |
| Hardware | Lenovo | Thinkagile 7y11 | - | All | All | All |
| Hardware | Lenovo | Thinkagile 7y12 | - | All | All | All |
| Hardware | Lenovo | Thinkagile 7y12 | - | All | All | All |
| Hardware | Lenovo | Thinkagile 7y13 | - | All | All | All |
| Hardware | Lenovo | Thinkagile 7y13 | - | All | All | All |
| Hardware | Lenovo | Thinkagile 7y14 | - | All | All | All |
| Hardware | Lenovo | Thinkagile 7y14 | - | All | All | All |
| Hardware | Lenovo | Thinkagile 7y88 | - | All | All | All |
| Hardware | Lenovo | Thinkagile 7y88 | - | All | All | All |
| Hardware | Lenovo | Thinkagile 7y90 | - | All | All | All |
| Hardware | Lenovo | Thinkagile 7y90 | - | All | All | All |
| Hardware | Lenovo | Thinkagile 7y92 | - | All | All | All |
| Hardware | Lenovo | Thinkagile 7y92 | - | All | All | All |
| Hardware | Lenovo | Thinkagile 7y93 | - | All | All | All |
| Hardware | Lenovo | Thinkagile 7y93 | - | All | All | All |
| Hardware | Lenovo | Thinkagile 7y94 | - | All | All | All |
| Hardware | Lenovo | Thinkagile 7y94 | - | All | All | All |
| Hardware | Lenovo | Thinkagile 7z03 | - | All | All | All |
| Hardware | Lenovo | Thinkagile 7z03 | - | All | All | All |
| Hardware | Lenovo | Thinkagile 7z04 | - | All | All | All |
| Hardware | Lenovo | Thinkagile 7z04 | - | All | All | All |
| Hardware | Lenovo | Thinkagile 7z05 | - | All | All | All |
| Hardware | Lenovo | Thinkagile 7z05 | - | All | All | All |
| Hardware | Lenovo | Thinkagile 7z06 | - | All | All | All |
| Hardware | Lenovo | Thinkagile 7z06 | - | All | All | All |
| Hardware | Lenovo | Thinkagile 7z07 | - | All | All | All |
| Hardware | Lenovo | Thinkagile 7z07 | - | All | All | All |
| Hardware | Lenovo | Thinkagile 7z20 | - | All | All | All |
| Hardware | Lenovo | Thinkagile 7z20 | - | All | All | All |
| Hardware | Lenovo | Thinkagile Yx84 | - | All | All | All |
| Hardware | Lenovo | Thinkagile Yx84 | - | All | All | All |
| Hardware | Lenovo | Thinksystem Sd530 | - | All | All | All |
| Hardware | Lenovo | Thinksystem Sd530 | - | All | All | All |
| Hardware | Lenovo | Thinksystem Sd650 | - | All | All | All |
| Hardware | Lenovo | Thinksystem Sd650 | - | All | All | All |
| Hardware | Lenovo | Thinksystem Sn550 | - | All | All | All |
| Hardware | Lenovo | Thinksystem Sn550 | - | All | All | All |
| Hardware | Lenovo | Thinksystem Sn850 | - | All | All | All |
| Hardware | Lenovo | Thinksystem Sn850 | - | All | All | All |
| Hardware | Lenovo | Thinksystem Sr150 | - | All | All | All |
| Hardware | Lenovo | Thinksystem Sr150 | - | All | All | All |
| Hardware | Lenovo | Thinksystem Sr158 | - | All | All | All |
| Hardware | Lenovo | Thinksystem Sr158 | - | All | All | All |
| Hardware | Lenovo | Thinksystem Sr250 | - | All | All | All |
| Hardware | Lenovo | Thinksystem Sr250 | - | All | All | All |
| Hardware | Lenovo | Thinksystem Sr258 | - | All | All | All |
| Hardware | Lenovo | Thinksystem Sr258 | - | All | All | All |
| Hardware | Lenovo | Thinksystem Sr530 | - | All | All | All |
| Hardware | Lenovo | Thinksystem Sr530 | - | All | All | All |
| Hardware | Lenovo | Thinksystem Sr550 | - | All | All | All |
| Hardware | Lenovo | Thinksystem Sr550 | - | All | All | All |
| Hardware | Lenovo | Thinksystem Sr570 | - | All | All | All |
| Hardware | Lenovo | Thinksystem Sr570 | - | All | All | All |
| Hardware | Lenovo | Thinksystem Sr590 | - | All | All | All |
| Hardware | Lenovo | Thinksystem Sr590 | - | All | All | All |
| Hardware | Lenovo | Thinksystem Sr630 | - | All | All | All |
| Hardware | Lenovo | Thinksystem Sr630 | - | All | All | All |
| Hardware | Lenovo | Thinksystem Sr650 | - | All | All | All |
| Hardware | Lenovo | Thinksystem Sr650 | - | All | All | All |
| Hardware | Lenovo | Thinksystem Sr850 | - | All | All | All |
| Hardware | Lenovo | Thinksystem Sr850 | - | All | All | All |
| Hardware | Lenovo | Thinksystem Sr860 | - | All | All | All |
| Hardware | Lenovo | Thinksystem Sr860 | - | All | All | All |
| Hardware | Lenovo | Thinksystem Sr950 | - | All | All | All |
| Hardware | Lenovo | Thinksystem Sr950 | - | All | All | All |
| Hardware | Lenovo | Thinksystem St250 | - | All | All | All |
| Hardware | Lenovo | Thinksystem St250 | - | All | All | All |
| Hardware | Lenovo | Thinksystem St258 | - | All | All | All |
| Hardware | Lenovo | Thinksystem St258 | - | All | All | All |
| Hardware | Lenovo | Thinksystem St550 | - | All | All | All |
| Hardware | Lenovo | Thinksystem St550 | - | All | All | All |
| Hardware | Lenovo | Thinksystem St558 | - | All | All | All |
| Hardware | Lenovo | Thinksystem St558 | - | All | All | All |
| Application | Lenovo | Xclarity Controller | All | All | All | All |
| Application | Lenovo | Xclarity Controller | All | All | All | All |
| Hardware | Lenovo | Thinksystem Sr670 | - | All | All | All |
| Hardware | Lenovo | Thinksystem Sr670 | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Lenovo XClarity Controller (XCC) Stored CSV Injection - Lenovo Support US | MISC | support.lenovo.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.