Security Advisory

CVE-2023-4608

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-10-24 20:25:49
Last updated 2024-09-11 20:38:29
Assigner lenovo
State PUBLISHED

Description

An authenticated XCC user with elevated privileges can perform blind SQL injection in limited cases through a crafted API command.  This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.