Vulnerabilities > Lenovo > Xclarity Administrator > 1.2.1

DATE CVE VULNERABILITY TITLE RISK
2017-06-20 CVE-2017-3745 Improper Authentication vulnerability in Lenovo Xclarity Administrator
In Lenovo XClarity Administrator (LXCA) before 1.3.0, if service data is downloaded from LXCA, a non-administrative user may have access to password information for users that have previously authenticated to the LXCA's internal LDAP server, including administrative accounts and service accounts with administrative privileges.
local
low complexity
lenovo CWE-287
2.1
2017-03-01 CVE-2016-8233 Information Exposure Through Log Files vulnerability in Lenovo Xclarity Administrator
Log files generated by Lenovo XClarity Administrator (LXCA) versions earlier than 1.2.2 may contain user credentials in a non-secure, clear text form that could be viewed by a non-privileged user.
network
low complexity
lenovo CWE-532
5.0