CVE-2019-6158: High severity Lenovo XClarity Administrator vulnerability
Published May 3, 2019
·Updated
An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered HTTP proxy credentials being written to a log file in clear text. This only affects LXCA when HTTP proxy credentials have been configured. This affects LXCA versions 2.0.0 to 2.3.x.
Affected Software
1 affected component
Lenovo XClarity Administrator>=2.0.0<2.4.0
Remediation
Information
Update your LXCA installation to version 2.4 or later.
Event History
May 3, 2019
CVE Published
via MITRE·07:27 PM
Data Sourced
via MITRE·07:27 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this security issue with Lenovo XClarity Administrator?
The vulnerability ID is CVE-2019-6158.
2
What is the severity of CVE-2019-6158?
The severity of CVE-2019-6158 is high.
3
What is affected by CVE-2019-6158?
Lenovo XClarity Administrator versions 2.0.0 to 2.3.x are affected by CVE-2019-6158.
4
How can I fix the vulnerability CVE-2019-6158?
To fix CVE-2019-6158, update Lenovo XClarity Administrator to version 2.4.0 or newer.
5
Are there any references related to CVE-2019-6158?
Yes, you can find more information about CVE-2019-6158 at the following references: http://www.securityfocus.com/bid/108165 and https://support.lenovo.com/solutions/LEN-26141.