Description
An unauthenticated XML external entity injection (XXE) vulnerability exists in LXCA's Common Information Model (CIM) server that could result in read-only access to specific files.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update LXCA to version 4.0 or later.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-43799 | An unauthenticated XML external entity injection (XXE) vulnerability exists in LXCA's Common Information Model (CIM) server that could result in read-only access to specific files. |
References
| Link | Providers |
|---|---|
| https://support.lenovo.com/us/en/product_security/LEN-98715 |
|
History
Tue, 03 Dec 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2024-12-03T18:32:53.195Z
Reserved: 2023-06-05T19:17:02.529Z
Link: CVE-2023-3113
Updated: 2024-08-02T06:48:07.103Z
Status : Modified
Published: 2023-06-26T20:15:10.653
Modified: 2024-11-21T08:16:29.327
Link: CVE-2023-3113
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD