CVE Published: 30/07/2018 |
CVE Updated: 16/09/2024 |
CVE Year: 2018 Source: lenovo |
Vendor: Lenovo Group Ltd. |
Product: Lenovo xClarity Administrator Status : PUBLISHED
CVE-2018-9066 Description
In Lenovo xClarity Administrator versions earlier than 2.1.0, an authenticated LXCA user can, under specific circumstances, inject additional parameters into a specific web API call which can result in privileged command execution within LXCA\'s underlying operating system.