Known Vulnerabilities
CVE-2023-4608
An authenticated XCC user with elevated privileges can perform blind SQL injection in limited cases through a crafted API command. This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.
MEDIUM
CVSS 4.1
Published Oct 24, 2023
CVE-2023-4607
An authenticated XCC user can change permissions for any user through a crafted API command.
HIGH
CVSS 7.5
Published Oct 24, 2023
CVE-2023-4606
An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command. This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.
HIGH
CVSS 8.1
Published Oct 24, 2023