Lenovo Xclarity Administrator vulnerabilities

30 known vulnerabilities affecting lenovo/xclarity_administrator.

Total CVEs
30
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH11MEDIUM17

Vulnerabilities

Page 1 of 2
CVE-2024-45102MEDIUMCVSS 6.8fixed in 4.12025-01-14
CVE-2024-45102 [MEDIUM] CWE-319 CVE-2024-45102: A privilege escalation vulnerability was discovered that could allow a valid, authenticated LXCA use A privilege escalation vulnerability was discovered that could allow a valid, authenticated LXCA user to escalate their permissions for a connected XCC instance when using LXCA as a Single Sign On (SSO) provider for XCC instances.
cvelistv5nvd
CVE-2024-45103MEDIUMCVSS 4.3fixed in 4.1.0fixed in 4.12024-09-13
CVE-2024-45103 [MEDIUM] CWE-282 CVE-2024-45103: A valid, authenticated LXCA user may be able to unmanage an LXCA managed device in through the LXCA A valid, authenticated LXCA user may be able to unmanage an LXCA managed device in through the LXCA web interface without sufficient privileges.
cvelistv5nvd
CVE-2024-45104MEDIUMCVSS 6.5fixed in 4.1.0fixed in 4.12024-09-13
CVE-2024-45104 [MEDIUM] CWE-282 CVE-2024-45104: A valid, authenticated LXCA user without sufficient privileges may be able to use the device identif A valid, authenticated LXCA user without sufficient privileges may be able to use the device identifier to modify an LXCA managed device through a specially crafted web API call.
cvelistv5nvd
CVE-2024-45101MEDIUMCVSS 6.8fixed in 4.12024-09-13
CVE-2024-45101 [MEDIUM] CWE-319 CVE-2024-45101: A privilege escalation vulnerability was discovered when Single Sign On (SSO) is enabled that could A privilege escalation vulnerability was discovered when Single Sign On (SSO) is enabled that could allow an attacker to intercept a valid, authenticated LXCA user’s XCC session if they can convince the user to click on a specially crafted URL.
cvelistv5nvd
CVE-2023-4605MEDIUMCVSS 6.5≥ , < 3.6.28≥ , < 4.0.242024-04-05
CVE-2023-4605 [MEDIUM] CWE-497 CVE-2023-4605: A valid authenticated Lenovo XClarity Administrator (LXCA) user can potentially leverage an unauthe A valid authenticated Lenovo XClarity Administrator (LXCA) user can potentially leverage an unauthenticated API endpoint to retrieve system event information.
cvelistv5nvd
CVE-2023-34418HIGHCVSS 8.1fixed in 4.0.02023-06-26
CVE-2023-34418 [HIGH] CWE-89 CVE-2023-34418: A valid, authenticated LXCA user may be able to gain unauthorized access to events and other data st A valid, authenticated LXCA user may be able to gain unauthorized access to events and other data stored in LXCA due to a SQL injection vulnerability in a specific web API.
nvd
CVE-2023-34420HIGHCVSS 7.2fixed in 4.0.02023-06-26
CVE-2023-34420 [HIGH] CWE-78 CVE-2023-34420: A valid, authenticated LXCA user with elevated privileges may be able to execute command injections A valid, authenticated LXCA user with elevated privileges may be able to execute command injections through crafted calls to a specific web API.
nvd
CVE-2023-3113HIGHCVSS 7.5fixed in 4.0.02023-06-26
CVE-2023-3113 [HIGH] CWE-611 CVE-2023-3113: An unauthenticated XML external entity injection (XXE) vulnerability exists in LXCA's Common Informa An unauthenticated XML external entity injection (XXE) vulnerability exists in LXCA's Common Information Model (CIM) server that could result in read-only access to specific files.
nvd
CVE-2023-34421MEDIUMCVSS 6.5fixed in 4.0.02023-06-26
CVE-2023-34421 [MEDIUM] CWE-20 CVE-2023-34421: A valid, authenticated LXCA user with elevated privileges may be able to replace filesystem data thr A valid, authenticated LXCA user with elevated privileges may be able to replace filesystem data through a specifically crafted web API call due to insufficient input validation.
nvd
CVE-2023-34422MEDIUMCVSS 6.5fixed in 4.0.02023-06-26
CVE-2023-34422 [MEDIUM] CWE-20 CVE-2023-34422: A valid, authenticated LXCA user with elevated privileges may be able to delete folders in the LXCA A valid, authenticated LXCA user with elevated privileges may be able to delete folders in the LXCA filesystem through a specifically crafted web API call due to insufficient input validation.
nvd
CVE-2020-8355MEDIUMCVSS 4.9fixed in 3.1.0≥ unspecified, < 3.1.02021-02-10
CVE-2020-8355 [MEDIUM] CWE-319 CVE-2020-8355: An internal product security audit of Lenovo XClarity Administrator (LXCA) prior to version 3.1.0 di An internal product security audit of Lenovo XClarity Administrator (LXCA) prior to version 3.1.0 discovered the Windows OS credentials provided by the LXCA user to perform driver updates of managed systems may be captured in the First Failure Data Capture (FFDC) service log if the service log is generated while managed endpoints are updating. The ser
cvelistv5nvd
CVE-2019-19756MEDIUMCVSS 6.0v2.6.02020-03-13
CVE-2019-19756 [HIGH] CWE-532 CVE-2019-19756: An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered Windows OS cre An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered Windows OS credentials, used to perform driver updates of managed systems, being written to a log file in clear text. This only affects LXCA version 2.6.0 when performing a Windows driver update. Affected logs are only accessible to authorized users in the First Fail
nvd
CVE-2019-6193HIGHCVSS 7.5fixed in 2.6.62020-02-14
CVE-2019-6193 [HIGH] CWE-284 CVE-2019-6193: An information disclosure vulnerability was reported in Lenovo XClarity Administrator (LXCA) version An information disclosure vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that could allow unauthenticated access to some configuration files which may contain usernames, license keys, IP addresses, and encrypted password hashes.
nvd
CVE-2019-6194MEDIUMCVSS 5.5fixed in 2.6.62020-02-14
CVE-2019-6194 [MEDIUM] CWE-611 CVE-2019-6194: An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that could allow information disclosure.
nvd
CVE-2019-19757MEDIUMCVSS 5.4fixed in 2.6.62020-02-14
CVE-2019-19757 [MEDIUM] CWE-79 CVE-2019-19757: An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered a Document Obj An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered a Document Object Model (DOM) based cross-site scripting vulnerability in versions prior to 2.6.6 that could allow JavaScript code to be executed in the user's web browser if a specially crafted link is visited. The JavaScript code is executed on the user's system,
nvd
CVE-2019-6179HIGHCVSS 7.5fixed in 2.5.02019-09-03
CVE-2019-6179 [HIGH] CWE-611 CVE-2019-6179: An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) prior to version 2.5.0 , Lenovo XClarity Integrator (LXCI) for Microsoft System Center prior to version 7.7.0, and Lenovo XClarity Integrator (LXCI) for VMWare vCenter prior to version 6.1.0 that could allow information disclosure.
nvd
CVE-2019-6181MEDIUMCVSS 6.1fixed in 2.5.02019-09-03
CVE-2019-6181 [MEDIUM] CWE-79 CVE-2019-6181: A reflected cross-site scripting (XSS) vulnerability was reported in Lenovo XClarity Administrator ( A reflected cross-site scripting (XSS) vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that could allow a crafted URL, if visited, to cause JavaScript code to be executed in the user's web browser. The JavaScript code is not executed on LXCA itself.
nvd
CVE-2019-6182MEDIUMCVSS 4.9fixed in 2.5.02019-09-03
CVE-2019-6182 [MEDIUM] CWE-1236 CVE-2019-6182: A stored CSV Injection vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions p A stored CSV Injection vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that could allow an administrative user to store malformed data in LXCA Jobs and Event Log data, that could result in crafted formulas stored in an exported CSV file. The crafted formula is not executed on LXCA itself.
nvd
CVE-2019-6180MEDIUMCVSS 4.8fixed in 2.5.02019-09-03
CVE-2019-6180 [MEDIUM] CWE-79 CVE-2019-6180: A stored cross-site scripting (XSS) vulnerability was reported in Lenovo XClarity Administrator (LXC A stored cross-site scripting (XSS) vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that could allow an administrative user to cause JavaScript code to be stored in LXCA which may then be executed in the user's web browser. The JavaScript code is not executed on LXCA itself.
nvd
CVE-2019-6158MEDIUMCVSS 5.9≥ 2.0.0, < 2.4.02019-05-03
CVE-2019-6158 [HIGH] CWE-532 CVE-2019-6158: An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered HTTP proxy cre An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered HTTP proxy credentials being written to a log file in clear text. This only affects LXCA when HTTP proxy credentials have been configured. This affects LXCA versions 2.0.0 to 2.3.x.
nvd