CVE-2018-16097

MEDIUM

Lenovo Xclarity Integrator < 3.5 - Unrestricted File Upload

Title source: rule
STIX 2.1

Description

LXCI for VMware versions prior to 5.5 and LXCI for Microsoft System Center versions prior to 3.5, allow an authenticated user to write to any system file due to insufficient sanitization during the upload of a certificate.

References (1)

Core 1
Core References
Patch, Vendor Advisory x_refsource_confirm
https://support.lenovo.com/us/en/solutions/LEN-23800

Scores

CVSS v3 6.5
EPSS 0.0012
EPSS Percentile 30.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-434
Status published
Products (2)
lenovo/xclarity_integrator < 3.5
lenovo/xclarity_integrator < 5.5
Published Nov 30, 2018
Tracked Since Feb 18, 2026