Vulnerability CVE-2023-25495


Published: 2023-04-28   Modified: 2023-04-29

Description:
A valid, authenticated administrative user can query a web interface API to reveal the configured LDAP client password used by XCC to authenticate to an external LDAP server in certain configurations. There is no exposure where no LDAP client password is configured

 References:
https://support.lenovo.com/us/en/product_security/LEN-99936

Copyright 2026, cxsecurity.com

 

Back to Top