"value":"\nA valid authenticated Lenovo XClarity Administrator (LXCA) user can potentially leverage an unauthenticated API endpoint to retrieve system event information.\n\n"
}
]
},
"problemtype":{
"problemtype_data":[
{
"description":[
{
"lang":"eng",
"value":"CWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere",
"value":"\n\n<p>Update to the Lenovo XClarity Administrator (LXCA) version (or higher) as recommended in the advisory: <a target=\"_blank\" rel=\"nofollow\" href=\"https://support.lenovo.com/us/en/product_security/LEN-136592\">https://support.lenovo.com/us/en/product_security/LEN-136592</a></p><p>Follow general security best practices, such as limiting access to only trusted users within the environment. </p><p>Only grant LXCA remote console/mount privileges to trusted administrative users.</p>"
}
],
"value":"\nUpdate to the Lenovo XClarity Administrator (LXCA) version (or higher) as recommended in the advisory:\u00a0 https://support.lenovo.com/us/en/product_security/LEN-136592 \n\nFollow general security best practices, such as limiting access to only trusted users within the environment. \n\nOnly grant LXCA remote console/mount privileges to trusted administrative users.\n\n"