CVE Feed

    Dashboard / CVE / CVE-2019-6187

    CVE-2019-6187

    A stored CSV Injection vulnerability was reported in Lenovo XClarity Controller (XCC) that could allow an administrative or other appropriately permissioned user to store malformed data in certain XCC server informational fields, that could result in crafted formulas being stored in an exported CSV file. The crafted formula is not executed on XCC itself and has no effect on the server.

    Published:Nov 20, 2019
    Last Modified:Nov 21, 2024
    EPS:Nov 20, 2019
    EPSS Score:0.00509
    CVSS Score:6.5

    Affected Products

    Vendor
    Lenovo
    Product
    Thinksystem Sr670
    Vendor
    Lenovo
    Product
    Thinkagile 7d1h
    Vendor
    Lenovo
    Product
    Thinkagile 7x82
    Vendor
    Lenovo
    Product
    Thinkagile 7x83
    Vendor
    Lenovo
    Product
    Thinkagile 7y11
    Vendor
    Lenovo
    Product
    Thinkagile 7y12
    Vendor
    Lenovo
    Product
    Thinkagile 7y13
    Vendor
    Lenovo
    Product
    Thinkagile 7y14
    Vendor
    Lenovo
    Product
    Thinkagile 7y88
    Vendor
    Lenovo
    Product
    Thinkagile 7y90
    Vendor
    Lenovo
    Product
    Thinkagile 7y92
    Vendor
    Lenovo
    Product
    Thinkagile 7y93
    Vendor
    Lenovo
    Product
    Thinkagile 7y94
    Vendor
    Lenovo
    Product
    Thinkagile 7z03
    Vendor
    Lenovo
    Product
    Thinkagile 7z04
    Vendor
    Lenovo
    Product
    Thinkagile 7z05
    Vendor
    Lenovo
    Product
    Thinkagile 7z06
    Vendor
    Lenovo
    Product
    Thinkagile 7z07
    Vendor
    Lenovo
    Product
    Thinkagile 7z20
    Vendor
    Lenovo
    Product
    Thinkagile Yx84
    Vendor
    Lenovo
    Product
    Thinksystem Sd530
    Vendor
    Lenovo
    Product
    Thinksystem Sd650
    Vendor
    Lenovo
    Product
    Thinksystem Sn550
    Vendor
    Lenovo
    Product
    Thinksystem Sn850
    Vendor
    Lenovo
    Product
    Thinksystem Sr150
    Vendor
    Lenovo
    Product
    Thinksystem Sr158
    Vendor
    Lenovo
    Product
    Thinksystem Sr250
    Vendor
    Lenovo
    Product
    Thinksystem Sr258
    Vendor
    Lenovo
    Product
    Thinksystem Sr530
    Vendor
    Lenovo
    Product
    Thinksystem Sr550
    Vendor
    Lenovo
    Product
    Thinksystem Sr570
    Vendor
    Lenovo
    Product
    Thinksystem Sr590
    Vendor
    Lenovo
    Product
    Thinksystem Sr630
    Vendor
    Lenovo
    Product
    Thinksystem Sr650
    Vendor
    Lenovo
    Product
    Thinksystem Sr850
    Vendor
    Lenovo
    Product
    Thinksystem Sr860
    Vendor
    Lenovo
    Product
    Thinksystem Sr950
    Vendor
    Lenovo
    Product
    Thinksystem St250
    Vendor
    Lenovo
    Product
    Thinksystem St258
    Vendor
    Lenovo
    Product
    Thinksystem St550
    Vendor
    Lenovo
    Product
    Thinksystem St558
    Vendor
    Lenovo
    Product
    Xclarity Controller

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High