CVE Published: 30/07/2018 |
CVE Updated: 16/09/2024 |
CVE Year: 2018 Source: lenovo |
Vendor: Lenovo Group Ltd. |
Product: Lenovo xClarity Administrator Status : PUBLISHED
CVE-2018-9064 Description
In Lenovo xClarity Administrator versions earlier than 2.1.0, an authenticated LXCA user may abuse a web API debug call to retrieve the credentials for the System Manager user.