PT-2023-29831 · Lenovo · Thinksystem

CVE-2023-4608

·

Published

2023-10-24

·

Updated

2023-11-07

CVSS v3.1

4.1

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions ThinkSystem versions v2 and v3
Description An authenticated XCC user with elevated privileges can perform blind SQL injection in limited cases through a crafted API command.
Recommendations For ThinkSystem versions v2 and v3, consider restricting access to the API until a patch is available. As a temporary workaround, limit the privileges of XCC users to minimize the risk of exploitation.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-4608

Affected Products

Thinksystem