First published: Fri Sep 13 2024(Updated: )
A privilege escalation vulnerability was discovered when Single Sign On (SSO) is enabled that could allow an attacker to intercept a valid, authenticated LXCA user’s XCC session if they can convince the user to click on a specially crafted URL.
Credit: psirt@lenovo.com
Update Lenovo XClarity Administrator to the version (or newer) indicated for your model in the advisory: https://support.lenovo.com/us/en/product_security/LEN-154748
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.