ID

VAR-201811-0501


CVE

CVE-2018-9072


TITLE

Vmware for LXCI Input validation vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2018-012838

DESCRIPTION

In versions prior to 5.5, LXCI for VMware allows an authenticated user to download any system file due to insufficient input sanitization during file downloads. Vmware for LXCI Contains an input validation vulnerability.Information may be obtained. Lenovo XClarity Integrator is prone to multiple security vulnerabilities: 1. An arbitrary-file-download vulnerability 2. An arbitrary file-overwrite vulnerability Attackers can overwrite arbitrary files on an unsuspecting user's computer in the context of the vulnerable application or download arbitrary files from the device filesystem and obtain potentially sensitive information.. The following versions of Lenovo XClarity Integrator are vulnerable: Lenovo XClarity Integrator for VMware versions prior to 5.5 are vulnerable.Lenovo XClarity Integrator for Microsoft System Center versions prior to 3.5 are vulnerable. Lenovo XClarity Integrator (LXCI) for Vmware is an application for Vmware from China Lenovo (Lenovo). The program offers extended capabilities such as infrastructure resource management, automation and IT service management. The vulnerability stems from the fact that the program does not adequately filter the input when downloading files

Trust: 1.98

sources: NVD: CVE-2018-9072 // JVNDB: JVNDB-2018-012838 // BID: 107583 // VULHUB: VHN-139104

AFFECTED PRODUCTS

vendor:lenovomodel:xclarity integratorscope:ltversion:5.5

Trust: 1.0

vendor:lenovomodel:xclarity integratorscope:ltversion:for vmware 5.5

Trust: 0.8

vendor:lenovomodel:xclarity integrator for vmware vcenterscope:eqversion:5.4

Trust: 0.3

vendor:lenovomodel:xclarity integrator for microsoft system centerscope:eqversion:3.4

Trust: 0.3

vendor:lenovomodel:xclarity integrator for vmware vcenterscope:neversion:5.5

Trust: 0.3

vendor:lenovomodel:xclarity integrator for microsoft system centerscope:neversion:3.5

Trust: 0.3

sources: BID: 107583 // JVNDB: JVNDB-2018-012838 // NVD: CVE-2018-9072

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-9072
value: MEDIUM

Trust: 1.0

NVD: CVE-2018-9072
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201812-010
value: MEDIUM

Trust: 0.6

VULHUB: VHN-139104
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2018-9072
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-139104
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-9072
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-139104 // JVNDB: JVNDB-2018-012838 // CNNVD: CNNVD-201812-010 // NVD: CVE-2018-9072

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.9

sources: VULHUB: VHN-139104 // JVNDB: JVNDB-2018-012838 // NVD: CVE-2018-9072

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201812-010

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-201812-010

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-012838

PATCH

title:LEN-23800url:https://support.lenovo.com/us/en/solutions/LEN-23800

Trust: 0.8

title:Lenovo XClarity Integrator for Vmware Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=87346

Trust: 0.6

sources: JVNDB: JVNDB-2018-012838 // CNNVD: CNNVD-201812-010

EXTERNAL IDS

db:NVDid:CVE-2018-9072

Trust: 2.8

db:LENOVOid:LEN-23800

Trust: 2.0

db:JVNDBid:JVNDB-2018-012838

Trust: 0.8

db:CNNVDid:CNNVD-201812-010

Trust: 0.7

db:BIDid:107583

Trust: 0.3

db:VULHUBid:VHN-139104

Trust: 0.1

sources: VULHUB: VHN-139104 // BID: 107583 // JVNDB: JVNDB-2018-012838 // CNNVD: CNNVD-201812-010 // NVD: CVE-2018-9072

REFERENCES

url:https://support.lenovo.com/us/en/solutions/len-23800

Trust: 1.7

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-9072

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-9072

Trust: 0.8

url:https://support.lenovo.com/in/en/solutions/lnvo-scvmadd

Trust: 0.3

url:https://support.lenovo.com/in/en/solutions/lnvo-vmware

Trust: 0.3

url:https://support.lenovo.com/in/en/solutions/len-23800

Trust: 0.3

sources: VULHUB: VHN-139104 // BID: 107583 // JVNDB: JVNDB-2018-012838 // CNNVD: CNNVD-201812-010 // NVD: CVE-2018-9072

CREDITS

Lenovo

Trust: 0.3

sources: BID: 107583

SOURCES

db:VULHUBid:VHN-139104
db:BIDid:107583
db:JVNDBid:JVNDB-2018-012838
db:CNNVDid:CNNVD-201812-010
db:NVDid:CVE-2018-9072

LAST UPDATE DATE

2024-11-23T22:12:13.898000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-139104date:2018-12-28T00:00:00
db:BIDid:107583date:2018-11-29T00:00:00
db:JVNDBid:JVNDB-2018-012838date:2019-02-08T00:00:00
db:CNNVDid:CNNVD-201812-010date:2018-12-03T00:00:00
db:NVDid:CVE-2018-9072date:2024-11-21T04:14:55.007

SOURCES RELEASE DATE

db:VULHUBid:VHN-139104date:2018-11-30T00:00:00
db:BIDid:107583date:2018-11-29T00:00:00
db:JVNDBid:JVNDB-2018-012838date:2019-02-08T00:00:00
db:CNNVDid:CNNVD-201812-010date:2018-12-03T00:00:00
db:NVDid:CVE-2018-9072date:2018-11-30T14:29:00.457