In Lenovo XClarity Administrator (LXCA) before 1.3.0, if service data is downloaded from LXCA, a non-administrative user may have access to password information for users that have previously authenticated to the LXCA's internal LDAP server, including administrative accounts and service accounts with administrative privileges. This is an issue only for users who have used local authentication with LXCA and not remote authentication against external LDAP or ADFS servers.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://support.lenovo.com/us/en/product_security/LEN-13671 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: lenovo
Published: 2017-06-20T00:00:00
Updated: 2024-08-05T14:39:41.321Z
Reserved: 2016-12-16T00:00:00
Link: CVE-2017-3745
Vulnrichment
No data.
NVD
Status : Modified
Published: 2017-06-20T00:29:00.360
Modified: 2024-11-21T03:26:03.330
Link: CVE-2017-3745
Redhat
No data.