CVE Vulnerabilities

CVE-2024-45104

Improper Ownership Management

Published: Sep 13, 2024 | Modified: Dec 13, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A valid, authenticated LXCA user without sufficient privileges may be able to use the device identifier to modify an LXCA managed device through a specially crafted web API call.

Weakness

The product assigns the wrong ownership, or does not properly verify the ownership, of an object or resource.

Affected Software

Name Vendor Start Version End Version
Xclarity_administrator Lenovo * 4.1.0 (excluding)

Potential Mitigations

References