CVE-2018-16097: Lenovo Xclarity Integrator

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

LXCI for VMware versions prior to 5.5 and LXCI for Microsoft System Center versions prior to 3.5, allow an authenticated user to write to any system file due to insufficient sanitization during the upload of a certificate.

Affected products

  • Lenovo Xclarity Integrator: before 3.5 (fixed in 3.5); before 5.5 (fixed in 5.5)

Published 2018-11-30. Last modified 2026-06-17.