Log files generated by Lenovo XClarity Administrator (LXCA) versions earlier than 1.2.2 may contain user credentials in a non-secure, clear text form that could be viewed by a non-privileged user.
The product writes sensitive information to a log file.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/95992 | vdb entry |
https://support.lenovo.com/us/en/product_security/LEN-11635 | patch vendor advisory mitigation |