Information Disclosure Vulnerability in Novell ZENworks Asset Management
CVE-2012-4933
Currently unrated
What is CVE-2012-4933?
The rtrlet web application within Novell ZENworks Asset Management 7.5 features hard-coded credentials that can be exploited by attackers to gain unauthorized access. Specifically, a hard-coded username 'Ivanhoe' and a password 'Scott' are used for the operations GetFile_Password and GetConfigInfo_Password. This flaw allows a remote attacker to manipulate requests directed at the HandleMaintenanceCalls function, potentially exposing sensitive information. Organizations using this product should take immediate action to secure their systems and review access controls.