PT-2020-11196 · Lenovo · Lenovo Xclarity Administrator
Published
2020-02-14
·
Updated
2020-02-24
·
CVE-2019-6193
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6
Description
An information disclosure issue was reported that could allow unauthenticated access to some configuration files. These files may contain sensitive information such as usernames, license keys, IP addresses, and encrypted password hashes.
Recommendations
For versions prior to 2.6.6, update to version 2.6.6 or later to resolve the issue.
Fix
Improper Access Control
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Lenovo Xclarity Administrator