CVE-2017-3764: Infoleak
A vulnerability was identified in Lenovo XClarity Administrator (LXCA) before 1.4.0 where LXCA user account names may be exposed to unauthenticated users with access to the LXCA web user interface. No password information of the user accounts is exposed.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3764?
The severity of CVE-2017-3764 is medium (5.3).
How does CVE-2017-3764 affect Lenovo XClarity Administrator (LXCA)?
CVE-2017-3764 exposes LXCA user account names to unauthenticated users with access to the LXCA web user interface.
Is any password information exposed in CVE-2017-3764?
No, CVE-2017-3764 does not expose any password information of the user accounts.
How can I fix CVE-2017-3764?
To fix CVE-2017-3764, upgrade Lenovo XClarity Administrator to version 1.4.0 or above.
Where can I find more information about CVE-2017-3764?
For more information about CVE-2017-3764, refer to the following link: [https://support.lenovo.com/us/en/product_security/LEN-16335](https://support.lenovo.com/us/en/product_security/LEN-16335)