CVE-2018-9072

MEDIUM

Lenovo XClarity Integrator < 5.5 - Authenticated Arbitrary File Read via File Download

Title source: llm
STIX 2.1

Description

In versions prior to 5.5, LXCI for VMware allows an authenticated user to download any system file due to insufficient input sanitization during file downloads.

References (1)

Core 1
Core References
Patch, Vendor Advisory x_refsource_confirm
https://support.lenovo.com/us/en/solutions/LEN-23800

Scores

CVSS v3 6.5
EPSS 0.0031
EPSS Percentile 54.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-20
Status published
Products (1)
lenovo/xclarity_integrator < 5.5
Published Nov 30, 2018
Tracked Since Feb 18, 2026