Symantec Altiris Deployment Solution 6.x before 6.9.355 SP1 stores the Application Identity Account password in memory in cleartext, which allows local users to gain privileges and modify clients of the Deployment Solution Server.
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Link | Tags |
---|---|
http://securityresponse.symantec.com/avcenter/security/Content/2008.10.20b.html | patch vendor advisory broken link |
http://secunia.com/advisories/31773 | broken link third party advisory vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/46007 | vdb entry third party advisory |
http://www.vupen.com/english/advisories/2008/2876 | vdb entry broken link patch vendor advisory |
http://www.securityfocus.com/bid/31767 | vdb entry third party advisory broken link |
http://www.securitytracker.com/id?1021072 | vdb entry third party advisory broken link |