User Account Information Exposure in Lenovo XClarity Administrator
CVE-2017-3764 
5.3MEDIUM
What is CVE-2017-3764?
A security flaw has been detected in Lenovo XClarity Administrator (LXCA) versions prior to 1.4.0. This vulnerability can lead to the exposure of LXCA user account names to unauthenticated users who have access to the LXCA web user interface. Importantly, while user account names may be visible, no password information is disclosed, reducing the scope of potential misuse. This issue highlights the importance of securing web interfaces to prevent unauthorized access to sensitive user data.
Affected Version(s)
xClarity Administrator Earlier than 1.4.0