In Lenovo xClarity Administrator versions earlier than 2.1.0, an authenticated LXCA user may abuse a web API debug call to retrieve the credentials for the System Manager user.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Xclarity_administrator | Lenovo | * | 2.1.0 (excluding) |
References