Web API Credential Exposure in Lenovo xClarity Administrator
CVE-2018-9064
8.8HIGH
What is CVE-2018-9064?
In Lenovo xClarity Administrator prior to version 2.1.0, authenticated users can exploit a flaw in the web API debug functionality to access sensitive credentials for the System Manager user account. This vulnerability can lead to unauthorized access, posing significant security risks to organizations relying on this management tool. Users are advised to upgrade to the latest version to mitigate potential attacks.
Affected Version(s)
Lenovo xClarity Administrator Earlier than 2.1.0