Description
The rtrlet web application in the Web Console in Novell ZENworks Asset Management (ZAM) 7.5 uses a hard-coded username of Ivanhoe and a hard-coded password of Scott for the (1) GetFile_Password and (2) GetConfigInfo_Password operations, which allows remote attackers to obtain sensitive information via a crafted rtrlet/rtr request for the HandleMaintenanceCalls function.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2024-08-06T20:50:18.017Z
Reserved: 2012-09-17T00:00:00.000Z
Link: CVE-2012-4933
No data.
Status : Modified
Published: 2012-10-20T18:55:01.303
Modified: 2026-04-29T01:13:23.040
Link: CVE-2012-4933
No data.
OpenCVE Enrichment
No data.
Weaknesses