Web API Credential Exposure in Lenovo xClarity Administrator
CVE-2018-9064
8.8HIGH
Summary
In Lenovo xClarity Administrator prior to version 2.1.0, authenticated users can exploit a flaw in the web API debug functionality to access sensitive credentials for the System Manager user account. This vulnerability can lead to unauthorized access, posing significant security risks to organizations relying on this management tool. Users are advised to upgrade to the latest version to mitigate potential attacks.
Affected Version(s)
Lenovo xClarity Administrator Earlier than 2.1.0
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved