PT-2018-18826 · Lenovo · Lenovo Xclarity Administrator

Published

2018-07-30

·

Updated

2019-10-03

·

CVE-2018-9065

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Lenovo xClarity Administrator versions prior to 2.1.0
Description The issue allows an attacker with access to the underlying LXCA file system user to potentially retrieve a credential store. This store contains service processor user names and passwords for servers previously managed by the LXCA instance. The attacker may also be able to decrypt these credentials more easily than intended.
Recommendations For versions prior to 2.1.0, update to version 2.1.0 or later to resolve the issue.

Fix

Cleartext Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-9065

Affected Products

Lenovo Xclarity Administrator