First published: Fri Feb 14 2020(Updated: )
An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that could allow information disclosure.
Credit: psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo XClarity Administrator | <2.6.6 |
Update your LXCA installation to version 2.6.6 or later. Installation note: You will need to update to LXCA 2.6.0 before installing the latest fix bundle (v 2.6.6).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-6194 is an XML External Entity (XXE) processing vulnerability in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6.
CVE-2019-6194 has a severity keyword of medium and a severity value of 5.5.
CVE-2019-6194 can allow information disclosure in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6.
To fix CVE-2019-6194, update Lenovo XClarity Administrator (LXCA) to version 2.6.6 or later.
You can find more information about CVE-2019-6194 on the Lenovo Product Security website.