CVE-2018-9072: Lenovo Xclarity Integrator

Medium severity, CVSS 6.5. EPSS: 0.9% chance of exploitation in the next 30 days.

In versions prior to 5.5, LXCI for VMware allows an authenticated user to download any system file due to insufficient input sanitization during file downloads.

Affected products

  • Lenovo Xclarity Integrator: before 5.5 (fixed in 5.5)

Published 2018-11-30. Last modified 2026-06-17.