First published: Thu Nov 30 2017(Updated: )
A vulnerability was identified in Lenovo XClarity Administrator (LXCA) before 1.4.0 where LXCA user account names may be exposed to unauthenticated users with access to the LXCA web user interface. No password information of the user accounts is exposed.
Credit: psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo XClarity Administrator | <1.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-3764 is medium (5.3).
CVE-2017-3764 exposes LXCA user account names to unauthenticated users with access to the LXCA web user interface.
No, CVE-2017-3764 does not expose any password information of the user accounts.
To fix CVE-2017-3764, upgrade Lenovo XClarity Administrator to version 1.4.0 or above.
For more information about CVE-2017-3764, refer to the following link: [https://support.lenovo.com/us/en/product_security/LEN-16335](https://support.lenovo.com/us/en/product_security/LEN-16335)