Description


A valid, authenticated administrative user can query a web interface API to reveal the configured LDAP client password used by XCC to authenticate to an external LDAP server in certain configurations. There is no exposure where no LDAP client password is configured

Related CPE's




o

lenovo

thinkagile_hx7530_firmware

2

h

lenovo

thinkagile_hx7530

2





















o

lenovo

thinkagile_hx2330_firmware

2












o

lenovo

thinkagile_hx3331_firmware

2

h

lenovo

thinkagile_hx3331

2



























o

lenovo

thinkagile_hx7531_firmware

2

h

lenovo

thinkagile_hx7531

2
























































































































































Weaknesses



CWE-522


CWE-522

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

4.9 · Medium

  • CVSS V3.1

  • CVSS V3.0

  • CVSS V2.0

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2023-04-28T22:15:08.950

2 years ago

Last modified

2023-05-09T20:36:34.067

2 years ago