Lenovo

Xclarity Administrator

30 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.05%
  • Veröffentlicht 14.01.2025 22:15:26
  • Zuletzt bearbeitet 14.01.2025 22:15:26

A privilege escalation vulnerability was discovered that could allow a valid, authenticated LXCA user to escalate their permissions for a connected XCC instance when using LXCA as a Single Sign On (SSO) provider for XCC instances.

  • EPSS 0.13%
  • Veröffentlicht 13.09.2024 18:15:05
  • Zuletzt bearbeitet 13.12.2024 19:19:54

A valid, authenticated LXCA user without sufficient privileges may be able to use the device identifier to modify an LXCA managed device through a specially crafted web API call.

  • EPSS 0.16%
  • Veröffentlicht 13.09.2024 18:15:04
  • Zuletzt bearbeitet 13.12.2024 19:19:52

A valid, authenticated LXCA user may be able to unmanage an LXCA managed device in through the LXCA web interface without sufficient privileges.

  • EPSS 0.1%
  • Veröffentlicht 13.09.2024 18:15:04
  • Zuletzt bearbeitet 14.09.2024 11:47:14

A privilege escalation vulnerability was discovered when Single Sign On (SSO) is enabled that could allow an attacker to intercept a valid, authenticated LXCA user’s XCC session if they can convince the user to click on a specially crafted URL.

  • EPSS 0.07%
  • Veröffentlicht 05.04.2024 21:15:08
  • Zuletzt bearbeitet 21.11.2024 08:35:31

A valid authenticated Lenovo XClarity Administrator (LXCA) user can potentially leverage an unauthenticated API endpoint to retrieve system event information.

  • EPSS 0.11%
  • Veröffentlicht 26.06.2023 20:15:10
  • Zuletzt bearbeitet 21.11.2024 08:16:29

An unauthenticated XML external entity injection (XXE) vulnerability exists in LXCA's Common Information Model (CIM) server that could result in read-only access to specific files.

  • EPSS 0.1%
  • Veröffentlicht 26.06.2023 20:15:10
  • Zuletzt bearbeitet 21.11.2024 08:07:12

A valid, authenticated LXCA user with elevated privileges may be able to delete folders in the LXCA filesystem through a specifically crafted web API call due to insufficient input validation.

  • EPSS 0.1%
  • Veröffentlicht 26.06.2023 20:15:10
  • Zuletzt bearbeitet 21.11.2024 08:07:12

A valid, authenticated LXCA user with elevated privileges may be able to replace filesystem data through a specifically crafted web API call due to insufficient input validation.

  • EPSS 0.33%
  • Veröffentlicht 26.06.2023 20:15:10
  • Zuletzt bearbeitet 21.11.2024 08:07:12

A valid, authenticated LXCA user with elevated privileges may be able to execute command injections through crafted calls to a specific web API.

  • EPSS 0.23%
  • Veröffentlicht 26.06.2023 20:15:10
  • Zuletzt bearbeitet 21.11.2024 08:07:11

A valid, authenticated LXCA user may be able to gain unauthorized access to events and other data stored in LXCA due to a SQL injection vulnerability in a specific web API.