Log files generated by Lenovo XClarity Administrator (LXCA) versions earlier than 1.2.2 may contain user credentials in a non-secure, clear text form that could be viewed by a non-privileged user.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HLenovo Xclarity Administrator
APPLenovo≤ 1.2.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2017-17833CRITICAL9.8PL ✓same product
OpenSLP — uszkodzenie pamięci sterty umożliwiające RCE lub DoS
CVE-2023-3113HIGH8.2same product
An unauthenticated XML external entity injection (XXE) vulnerability exists in LXCA's Common Information Model...
CVE-2023-34420HIGH7.2same product
A valid, authenticated LXCA user with elevated privileges may be able to execute command injections through cr...
CVE-2023-34418HIGH8.1same product
A valid, authenticated LXCA user may be able to gain unauthorized access to events and other data stored in LX...
CVE-2019-19756HIGH7.9same product
An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered Windows OS credentials, ...