CVE-2019-19756
13.03.2020, 16:15
An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered Windows OS credentials, used to perform driver updates of managed systems, being written to a log file in clear text. This only affects LXCA version 2.6.0 when performing a Windows driver update. Affected logs are only accessible to authorized users in the First Failure Data Capture (FFDC) service log and log files on LXCA.Enginsight
Vendor | Product | Version |
---|---|---|
lenovo | xclarity_administrator | 2.6.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration