Description
In Lenovo XClarity Administrator (LXCA) before 1.3.0, if service data is downloaded from LXCA, a non-administrative user may have access to password information for users that have previously authenticated to the LXCA's internal LDAP server, including administrative accounts and service accounts with administrative privileges. This is an issue only for users who have used local authentication with LXCA and not remote authentication against external LDAP or ADFS servers.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-12862 | In Lenovo XClarity Administrator (LXCA) before 1.3.0, if service data is downloaded from LXCA, a non-administrative user may have access to password information for users that have previously authenticated to the LXCA's internal LDAP server, including administrative accounts and service accounts with administrative privileges. This is an issue only for users who have used local authentication with LXCA and not remote authentication against external LDAP or ADFS servers. |
References
| Link | Providers |
|---|---|
| https://support.lenovo.com/us/en/product_security/LEN-13671 |
|
History
No history.
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2024-08-05T14:39:41.321Z
Reserved: 2016-12-16T00:00:00.000Z
Link: CVE-2017-3745
No data.
Status : Deferred
Published: 2017-06-20T00:29:00.360
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-3745
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD