CVE-2019-6194: Lenovo Xclarity Administrator

Medium severity, CVSS 5.5. EPSS: 0.7% chance of exploitation in the next 30 days.

An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that could allow information disclosure.

Affected products

  • Lenovo Xclarity Administrator: before 2.6.6 (fixed in 2.6.6)

Published 2020-02-14. Last modified 2026-06-17.