First published: Mon Jul 30 2018(Updated: )
In Lenovo xClarity Administrator versions earlier than 2.1.0, an authenticated LXCA user may abuse a web API debug call to retrieve the credentials for the System Manager user.
Credit: psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo XClarity Administrator | <2.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2018-9064.
The title of this vulnerability is 'In Lenovo xClarity Administrator versions earlier than 2.1.0 an authenticated LXCA user may abuse a ...'
The severity of CVE-2018-9064 is high with a severity value of 8.8.
Lenovo xClarity Administrator versions earlier than 2.1.0 are affected by CVE-2018-9064.
To fix CVE-2018-9064, update Lenovo xClarity Administrator to version 2.1.0 or later.