CVE-2020-8355
- EPSS 0.11%
- Veröffentlicht 10.02.2021 21:15:13
- Zuletzt bearbeitet 21.11.2024 05:38:46
An internal product security audit of Lenovo XClarity Administrator (LXCA) prior to version 3.1.0 discovered the Windows OS credentials provided by the LXCA user to perform driver updates of managed systems may be captured in the First Failure Data C...
- EPSS 0.14%
- Veröffentlicht 13.03.2020 16:15:11
- Zuletzt bearbeitet 21.11.2024 04:35:19
An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered Windows OS credentials, used to perform driver updates of managed systems, being written to a log file in clear text. This only affects LXCA version 2.6.0 when perf...
CVE-2019-6194
- EPSS 0.25%
- Veröffentlicht 14.02.2020 17:15:13
- Zuletzt bearbeitet 21.11.2024 04:46:09
An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that could allow information disclosure.
CVE-2019-6193
- EPSS 0.34%
- Veröffentlicht 14.02.2020 17:15:13
- Zuletzt bearbeitet 21.11.2024 04:46:08
An information disclosure vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that could allow unauthenticated access to some configuration files which may contain usernames, license keys, IP addresses, and encr...
CVE-2019-19757
- EPSS 0.31%
- Veröffentlicht 14.02.2020 17:15:11
- Zuletzt bearbeitet 21.11.2024 04:35:20
An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered a Document Object Model (DOM) based cross-site scripting vulnerability in versions prior to 2.6.6 that could allow JavaScript code to be executed in the user's web ...
CVE-2019-6182
- EPSS 0.26%
- Veröffentlicht 03.09.2019 19:15:10
- Zuletzt bearbeitet 21.11.2024 04:46:07
A stored CSV Injection vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that could allow an administrative user to store malformed data in LXCA Jobs and Event Log data, that could result in crafted formulas s...
CVE-2019-6181
- EPSS 0.32%
- Veröffentlicht 03.09.2019 19:15:10
- Zuletzt bearbeitet 21.11.2024 04:46:06
A reflected cross-site scripting (XSS) vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that could allow a crafted URL, if visited, to cause JavaScript code to be executed in the user's web browser. The JavaS...
CVE-2019-6180
- EPSS 0.27%
- Veröffentlicht 03.09.2019 19:15:10
- Zuletzt bearbeitet 21.11.2024 04:46:06
A stored cross-site scripting (XSS) vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that could allow an administrative user to cause JavaScript code to be stored in LXCA which may then be executed in the use...
CVE-2019-6179
- EPSS 0.29%
- Veröffentlicht 03.09.2019 19:15:10
- Zuletzt bearbeitet 21.11.2024 04:46:06
An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) prior to version 2.5.0 , Lenovo XClarity Integrator (LXCI) for Microsoft System Center prior to version 7.7.0, and Lenovo XClarity Integrator (...
CVE-2019-6158
- EPSS 0.32%
- Veröffentlicht 03.05.2019 20:29:01
- Zuletzt bearbeitet 21.11.2024 04:46:03
An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered HTTP proxy credentials being written to a log file in clear text. This only affects LXCA when HTTP proxy credentials have been configured. This affects LXCA version...