Lenovo Xclarity Orchestrator
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Lenovo Xclarity Orchestrator.
By the Year
In 2026 there have been 0 vulnerabilities in Lenovo Xclarity Orchestrator. Last year, in 2025 Xclarity Orchestrator had 1 security vulnerability published. Right now, Xclarity Orchestrator is on track to have less security vulnerabilities in 2026 than it did last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 0 | 0.00 |
| 2025 | 1 | 8.80 |
| 2024 | 0 | 0.00 |
| 2023 | 0 | 0.00 |
| 2022 | 0 | 0.00 |
| 2021 | 2 | 4.90 |
It may take a day or so for new Xclarity Orchestrator vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Lenovo Xclarity Orchestrator Security Vulnerabilities
Lenovo XClarity Orchestrator Local Network API Channel Abuse
CVE-2025-8557
8.8 - High
- September 11, 2025
An internal product security audit of Lenovo XClarity Orchestrator (LXCO) discovered the below vulnerability: An attacker with access to a device on the local Lenovo XClarity Orchestrator (LXCO) network segment may be able to manipulate the local device to create an alternate communication channel which could allow the attacker, under certain conditions, to directly interact with backend LXCO API services typically inaccessible to users. While access controls may limit the scope of interaction, this could result in unauthorized access to internal functionality or data. This issue is not exploitable from remote networks.
Unprotected Alternate Channel
An internal product security audit of LXCO, prior to version 1.2.2, discovered
CVE-2021-3417
4.9 - Medium
- March 09, 2021
An internal product security audit of LXCO, prior to version 1.2.2, discovered that credentials for Lenovo XClarity Administrator (LXCA), if added as a Resource Manager, are encoded then written to an internal LXCO log file each time a session is established with LXCA. Affected logs are captured in the First Failure Data Capture (FFDC) service log. The FFDC service log is only generated when requested by a privileged LXCO user and it is only accessible to the privileged LXCO user that requested the file.
Cleartext Transmission of Sensitive Information
An internal product security audit of LXCO, prior to version 1.2.2, discovered
CVE-2020-8356
4.9 - Medium
- March 09, 2021
An internal product security audit of LXCO, prior to version 1.2.2, discovered that optional passwords, if specified, for the Syslog and SMTP forwarders are written to an internal LXCO log file in clear text. Affected logs are captured in the First Failure Data Capture (FFDC) service log. The FFDC service log is only generated when requested by a privileged LXCO user and it is only accessible to the privileged LXCO user that requested the file.
Cleartext Transmission of Sensitive Information
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Lenovo Xclarity Orchestrator or by Lenovo? Click the Watch button to subscribe.