CVE-2018-9064: High severity lenovo xclarity administrator vulnerability
Published Jul 30, 2018
·Updated
In Lenovo xClarity Administrator versions earlier than 2.1.0, an authenticated LXCA user may abuse a web API debug call to retrieve the credentials for the System Manager user.
Affected Software
1 affected component
Lenovo XClarity Administrator<2.1.0
Event History
Jul 30, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2018-9064.
2
What is the title of this vulnerability?
The title of this vulnerability is 'In Lenovo xClarity Administrator versions earlier than 2.1.0 an authenticated LXCA user may abuse a ...'
3
What is the severity of CVE-2018-9064?
The severity of CVE-2018-9064 is high with a severity value of 8.8.
4
What software versions are affected by CVE-2018-9064?
Lenovo xClarity Administrator versions earlier than 2.1.0 are affected by CVE-2018-9064.
5
How can I fix CVE-2018-9064?
To fix CVE-2018-9064, update Lenovo xClarity Administrator to version 2.1.0 or later.