This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to the product version (or newer) indicated for your model in the advisory: https://support.lenovo.com/us/en/product_security/LEN-140960
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-54461 | An authenticated XCC user with elevated privileges can perform blind SQL injection in limited cases through a crafted API command. This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected. |
| Link | Providers |
|---|---|
| https://support.lenovo.com/us/en/product_security/LEN-140960 |
|
No history.
Subscriptions
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2024-09-11T20:38:29.704Z
Reserved: 2023-08-29T15:54:56.119Z
Link: CVE-2023-4608
Updated: 2024-08-02T07:31:06.539Z
Status : Modified
Published: 2023-10-25T18:17:41.670
Modified: 2026-06-17T06:38:13.017
Link: CVE-2023-4608
No data.
OpenCVE Enrichment
No data.
-
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
EUVD