An authenticated XCC user with elevated privileges can perform blind SQL injection in limited cases through a crafted API command.  This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: lenovo

Published: 2023-10-24T20:25:49.416Z

Updated: 2023-10-24T20:25:49.416Z

Reserved: 2023-08-29T15:54:56.119Z


Link: CVE-2023-4608

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-10-25T18:17:41.670

Modified: 2023-11-07T19:15:44.413


Link: CVE-2023-4608

JSON object: View

cve-icon Redhat Information

No data.

CWE