漏洞信息详情
多款Lenovo产品日志信息泄露漏洞
漏洞简介
Lenovo Flex System x240 M4等都是中国联想(Lenovo)公司的一款服务器。
多款Lenovo产品中存在安全漏洞,该漏洞源于FFDC将Web服务器的私钥记录在日志文件中。攻击者可利用该漏洞泄露信息。以下产品受到影响:Lenovo Flex System x240 M4;Flex System x240 M5;Flex System x280 X6;Flex System x440 M4;Flex System x480 X6;Flex System x880;NeXtScale nx360 M5;System x3250 M6;System x3500 M5;System x3550 M5 (ThinkAgile CX2200/4200/4600);System x3650 M5;System x3750 M4;System x3850 X6;System x3950 X6;BladeCenter HS22;BladeCenter HS23;BladeCenter HS23E;Flex System x220 M4;Flex System x222 M4;Flex System x240 M4;Flex System x280 M4;Flex System x440 M4;Flex System x480 M4;Flex System x880 M4;iDataPlex dx360 M4;iDataPlex dx360 M4 Water Cooled;NeXtScale nx360 M4;System x3100 M4;System x3100 M5;System x3250 M4;System x3250 M5;System x3300 M4;System x3500 M4;System x3530 M4;System x3550 M4;System x3630 M4;System x3650 M4;System x3650 M4 BD;System x3650 M4 HD;System x3750 M4;System x3850 X6;System x3950 X6。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://support.lenovo.com/us/en/solutions/len-25667
参考网址
来源:support.lenovo.com
链接:https://support.lenovo.com/solutions/LEN-25667
来源:www.ibm.com
链接:http://www.ibm.com/support/docview.wss
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2019-6157
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/79722
来源:www-01.ibm.com
链接:https://www-01.ibm.com/support/docview.wss?uid=ibm10882394
来源:support.lenovo.com
链接:https://support.lenovo.com/us/en/solutions/len-25667
受影响实体
暂无
补丁
- 多款Lenovo产品安全漏洞的修复措施<!--2019-4-19-->
还没有评论,来说两句吧...