CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

lenovo

xclarity_administrator

21 known vulnerabilities · sorted by CVSS score

CVE-2017-17833
CRITICAL9.8

OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-service or a remote code-execution vulnerability.

openslp / openslp+43
Network
Published Apr 23, 2018
Page 1 of 2
CVE-2018-9064
HIGH8.8

In Lenovo xClarity Administrator versions earlier than 2.1.0, an authenticated LXCA user may abuse a web API debug call to retrieve the credentials for the System Manager user.

lenovo / xclarity_administrator
Network
Published Jul 30, 2018
CVE-2018-9066
HIGH8.8

In Lenovo xClarity Administrator versions earlier than 2.1.0, an authenticated LXCA user can, under specific circumstances, inject additional parameters into a specific web API call which can result in privileged command execution within LXCA's underlying operating system.

lenovo / xclarity_administrator
Network
Published Jul 30, 2018
CVE-2019-6158
HIGH8.7

An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered HTTP proxy credentials being written to a log file in clear text. This only affects LXCA when HTTP proxy credentials have been configured. This affects LXCA versions 2.0.0 to 2.3.x.

lenovo / xclarity_administrator
Network
Published May 3, 2019
CVE-2023-3113
HIGH8.2

An unauthenticated XML external entity injection (XXE) vulnerability exists in LXCA's Common Information Model (CIM) server that could result in read-only access to specific files.

lenovo / xclarity_administrator
Network
Published Jun 26, 2023
CVE-2023-34418
HIGH8.1

A valid, authenticated LXCA user may be able to gain unauthorized access to events and other data stored in LXCA due to a SQL injection vulnerability in a specific web API.

lenovo / xclarity_administrator
Network
Published Jun 26, 2023
CVE-2019-19756
HIGH7.9

An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered Windows OS credentials, used to perform driver updates of managed systems, being written to a log file in clear text. This only affects LXCA version 2.6.0 when performing a Windows driver update. Affected logs are only accessible to authorized users in the First Failure Data Capture (FFDC) service log and log files on LXCA.

lenovo / xclarity_administrator
Local
Published Mar 13, 2020
CVE-2018-9065
HIGH7.5

In Lenovo xClarity Administrator versions earlier than 2.1.0, an attacker that gains access to the underlying LXCA file system user may be able to retrieve a credential store containing the service processor user names and passwords for servers previously managed by that LXCA instance, and potentially decrypt those credentials more easily than intended.

lenovo / xclarity_administrator
Network
Published Jul 30, 2018
CVE-2019-6179
HIGH7.5

An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) prior to version 2.5.0 , Lenovo XClarity Integrator (LXCI) for Microsoft System Center prior to version 7.7.0, and Lenovo XClarity Integrator (LXCI) for VMWare vCenter prior to version 6.1.0 that could allow information disclosure.

lenovo / xclarity_administrator+2
Network
Published Sep 3, 2019
CVE-2019-6193
HIGH7.5

An information disclosure vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that could allow unauthenticated access to some configuration files which may contain usernames, license keys, IP addresses, and encrypted password hashes.

lenovo / xclarity_administrator
Network
Published Feb 14, 2020
CVE-2023-34420
HIGH7.2

A valid, authenticated LXCA user with elevated privileges may be able to execute command injections through crafted calls to a specific web API.

lenovo / xclarity_administrator
Network
Published Jun 26, 2023
CVE-2023-34421
MEDIUM6.5

A valid, authenticated LXCA user with elevated privileges may be able to replace filesystem data through a specifically crafted web API call due to insufficient input validation.

lenovo / xclarity_administrator
Network
Published Jun 26, 2023
CVE-2023-34422
MEDIUM6.5

A valid, authenticated LXCA user with elevated privileges may be able to delete folders in the LXCA filesystem through a specifically crafted web API call due to insufficient input validation.

lenovo / xclarity_administrator
Network
Published Jun 26, 2023
CVE-2024-45104
MEDIUM6.3

A valid, authenticated LXCA user without sufficient privileges may be able to use the device identifier to modify an LXCA managed device through a specially crafted web API call.

lenovo / xclarity_administrator
Network
Published Sep 13, 2024
CVE-2019-6181
MEDIUM6.1

A reflected cross-site scripting (XSS) vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that could allow a crafted URL, if visited, to cause JavaScript code to be executed in the user's web browser. The JavaScript code is not executed on LXCA itself.

lenovo / xclarity_administrator
Network
Published Sep 3, 2019
CVE-2019-6194
MEDIUM5.7

An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that could allow information disclosure.

lenovo / xclarity_administrator
Network
Published Feb 14, 2020
CVE-2019-19757
MEDIUM5.4

An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered a Document Object Model (DOM) based cross-site scripting vulnerability in versions prior to 2.6.6 that could allow JavaScript code to be executed in the user's web browser if a specially crafted link is visited. The JavaScript code is executed on the user's system, not executed on LXCA itself.

lenovo / xclarity_administrator
Network
Published Feb 14, 2020
CVE-2019-6182
MEDIUM4.9

A stored CSV Injection vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that could allow an administrative user to store malformed data in LXCA Jobs and Event Log data, that could result in crafted formulas stored in an exported CSV file. The crafted formula is not executed on LXCA itself.

lenovo / xclarity_administrator
Network
Published Sep 3, 2019
CVE-2020-8355
MEDIUM4.9

An internal product security audit of Lenovo XClarity Administrator (LXCA) prior to version 3.1.0 discovered the Windows OS credentials provided by the LXCA user to perform driver updates of managed systems may be captured in the First Failure Data Capture (FFDC) service log if the service log is generated while managed endpoints are updating. The service log is only generated when requested by a privileged LXCA user and it is only accessible to the privileged LXCA user that requested the file and is then deleted.

lenovo / xclarity_administrator
Network
Published Feb 10, 2021
CVE-2019-6180
MEDIUM4.8

A stored cross-site scripting (XSS) vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that could allow an administrative user to cause JavaScript code to be stored in LXCA which may then be executed in the user's web browser. The JavaScript code is not executed on LXCA itself.

lenovo / xclarity_administrator
Network
Published Sep 3, 2019