CVE-2019-6187
A stored CSV Injection vulnerability was reported in Lenovo XClarity Controller (XCC) that could allow an administrative or other appropriately permissioned user to store malformed data in certain XCC server informational fields, that could result in crafted formulas being stored in an exported CSV file. The crafted formula is not executed on XCC itself and has no effect on the server.
Published:Nov 20, 2019
Last Modified:Nov 21, 2024
EPS:Nov 20, 2019
EPSS Score:0.00509
CVSS Score:6.5
Affected Products
Vendor
Product
Action
Vendor
Lenovo
Product
Thinksystem Sr670
Lenovo
Thinksystem Sr670
Vendor
Lenovo
Product
Thinkagile 7d1h
Lenovo
Thinkagile 7d1h
Vendor
Lenovo
Product
Thinkagile 7x82
Lenovo
Thinkagile 7x82
Vendor
Lenovo
Product
Thinkagile 7x83
Lenovo
Thinkagile 7x83
Vendor
Lenovo
Product
Thinkagile 7y11
Lenovo
Thinkagile 7y11
Vendor
Lenovo
Product
Thinkagile 7y12
Lenovo
Thinkagile 7y12
Vendor
Lenovo
Product
Thinkagile 7y13
Lenovo
Thinkagile 7y13
Vendor
Lenovo
Product
Thinkagile 7y14
Lenovo
Thinkagile 7y14
Vendor
Lenovo
Product
Thinkagile 7y88
Lenovo
Thinkagile 7y88
Vendor
Lenovo
Product
Thinkagile 7y90
Lenovo
Thinkagile 7y90
Vendor
Lenovo
Product
Thinkagile 7y92
Lenovo
Thinkagile 7y92
Vendor
Lenovo
Product
Thinkagile 7y93
Lenovo
Thinkagile 7y93
Vendor
Lenovo
Product
Thinkagile 7y94
Lenovo
Thinkagile 7y94
Vendor
Lenovo
Product
Thinkagile 7z03
Lenovo
Thinkagile 7z03
Vendor
Lenovo
Product
Thinkagile 7z04
Lenovo
Thinkagile 7z04
Vendor
Lenovo
Product
Thinkagile 7z05
Lenovo
Thinkagile 7z05
Vendor
Lenovo
Product
Thinkagile 7z06
Lenovo
Thinkagile 7z06
Vendor
Lenovo
Product
Thinkagile 7z07
Lenovo
Thinkagile 7z07
Vendor
Lenovo
Product
Thinkagile 7z20
Lenovo
Thinkagile 7z20
Vendor
Lenovo
Product
Thinkagile Yx84
Lenovo
Thinkagile Yx84
Vendor
Lenovo
Product
Thinksystem Sd530
Lenovo
Thinksystem Sd530
Vendor
Lenovo
Product
Thinksystem Sd650
Lenovo
Thinksystem Sd650
Vendor
Lenovo
Product
Thinksystem Sn550
Lenovo
Thinksystem Sn550
Vendor
Lenovo
Product
Thinksystem Sn850
Lenovo
Thinksystem Sn850
Vendor
Lenovo
Product
Thinksystem Sr150
Lenovo
Thinksystem Sr150
Vendor
Lenovo
Product
Thinksystem Sr158
Lenovo
Thinksystem Sr158
Vendor
Lenovo
Product
Thinksystem Sr250
Lenovo
Thinksystem Sr250
Vendor
Lenovo
Product
Thinksystem Sr258
Lenovo
Thinksystem Sr258
Vendor
Lenovo
Product
Thinksystem Sr530
Lenovo
Thinksystem Sr530
Vendor
Lenovo
Product
Thinksystem Sr550
Lenovo
Thinksystem Sr550
Vendor
Lenovo
Product
Thinksystem Sr570
Lenovo
Thinksystem Sr570
Vendor
Lenovo
Product
Thinksystem Sr590
Lenovo
Thinksystem Sr590
Vendor
Lenovo
Product
Thinksystem Sr630
Lenovo
Thinksystem Sr630
Vendor
Lenovo
Product
Thinksystem Sr650
Lenovo
Thinksystem Sr650
Vendor
Lenovo
Product
Thinksystem Sr850
Lenovo
Thinksystem Sr850
Vendor
Lenovo
Product
Thinksystem Sr860
Lenovo
Thinksystem Sr860
Vendor
Lenovo
Product
Thinksystem Sr950
Lenovo
Thinksystem Sr950
Vendor
Lenovo
Product
Thinksystem St250
Lenovo
Thinksystem St250
Vendor
Lenovo
Product
Thinksystem St258
Lenovo
Thinksystem St258
Vendor
Lenovo
Product
Thinksystem St550
Lenovo
Thinksystem St550
Vendor
Lenovo
Product
Thinksystem St558
Lenovo
Thinksystem St558
Vendor
Lenovo
Product
Xclarity Controller
Lenovo
Xclarity Controller
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
