PT-2019-17991 · Lenovo · Lenovo Xclarity Administrator

Publicado

2019-05-03

·

Atualizado

2019-10-09

·

CVE-2019-6158

CVSS v3.1

8.7

Alta

VetorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Lenovo XClarity Administrator versions 2.0.0 through 2.3.x
Description An internal product security audit discovered that HTTP proxy credentials are being written to a log file in clear text when HTTP proxy credentials have been configured.
Recommendations For versions 2.0.0 through 2.3.x, consider removing or securely storing HTTP proxy credentials to prevent them from being written to log files in clear text. As a temporary workaround, restrict access to log files to minimize the risk of exploitation.

Correção

Insertion into Log File

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-6158

Produtos afetados

Lenovo Xclarity Administrator