CVE-2019-6195

An authorization bypass exists in Lenovo XClarity Controller (XCC) versions prior to 3.08 CDI340V, 3.01 TEI392O, 1.71 PSI328N where a valid authenticated user with lesser privileges may be granted read-only access to higher-privileged information if 1) “LDAP Authentication Only with Local Authorization” mode is configured and used by XCC, and 2) a lesser privileged user logs into XCC within 1 minute of a higher privileged user logging out. The authorization bypass does not exist when “Local Authentication and Authorization” or “LDAP Authentication and Authorization” modes are configured and used by XCC.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:lenovo:xclarity_controller:*:*:*:*:*:*:*:*
OR cpe:2.3:h:lenovo:thinkagile_hx_1000:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkagile_hx_2000:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkagile_hx_3000:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkagile_hx_5000:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkagile_hx_7000:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkagile_vx_1000:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkagile_vx_2000:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkagile_vx_3000:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkagile_vx_5000:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkagile_vx_7000:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinksystem_sd530:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinksystem_sd650_dwc:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinksystem_sn550:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinksystem_sn850:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinksystem_sr150:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinksystem_sr158:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinksystem_sr250:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinksystem_sr258:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinksystem_sr850:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinksystem_sr860:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinksystem_st250:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinksystem_st258:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:lenovo:xclarity_controller:*:*:*:*:*:*:*:*
OR cpe:2.3:h:lenovo:thinkagile_hx_1000:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkagile_hx_2000:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkagile_hx_3000:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkagile_hx_5000:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkagile_hx_7000:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkagile_mx_sr650:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkagile_vx_1000:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkagile_vx_2000:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkagile_vx_3000:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkagile_vx_5000:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinkagile_vx_7000:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinksystem_sr530:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinksystem_sr550:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinksystem_sr570:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinksystem_sr590:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinksystem_sr630:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinksystem_sr650:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinksystem_st550:-:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinksystem_st558:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:a:lenovo:xclarity_controller:*:*:*:*:*:*:*:*
cpe:2.3:h:lenovo:thinksystem_sr950_server:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:46

Type Values Removed Values Added
References () https://support.lenovo.com/us/en/product_security/LEN-29116 - Vendor Advisory () https://support.lenovo.com/us/en/product_security/LEN-29116 - Vendor Advisory

Information

Published : 2020-02-14 17:15

Updated : 2024-11-21 04:46


NVD link : CVE-2019-6195

Mitre link : CVE-2019-6195

CVE.ORG link : CVE-2019-6195


JSON object : View

Products Affected

lenovo

  • thinksystem_sr590
  • thinksystem_sr530
  • xclarity_controller
  • thinkagile_vx_5000
  • thinksystem_sr850
  • thinksystem_st250
  • thinksystem_sr950_server
  • thinkagile_hx_1000
  • thinksystem_st558
  • thinkagile_vx_1000
  • thinksystem_sr250
  • thinkagile_vx_3000
  • thinkagile_vx_2000
  • thinksystem_sn550
  • thinksystem_sr550
  • thinksystem_sr150
  • thinksystem_sr258
  • thinksystem_sr630
  • thinkagile_hx_7000
  • thinksystem_st550
  • thinkagile_hx_5000
  • thinkagile_vx_7000
  • thinksystem_sd650_dwc
  • thinksystem_sr860
  • thinkagile_mx_sr650
  • thinksystem_st258
  • thinkagile_hx_3000
  • thinksystem_sr650
  • thinksystem_sr158
  • thinksystem_sn850
  • thinksystem_sr570
  • thinkagile_hx_2000
  • thinksystem_sd530
CWE
CWE-264

Permissions, Privileges, and Access Controls

CWE-269

Improper Privilege Management