icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons_061

Altiris Deployment Solution Server < 6.9.355 Password Disclosure (SYM08-020)

Medium

Synopsis

The remote Windows host has a program that is affected by a password disclosure vulnerability.

Description

The version of the Altiris Deployment Solution installed on the remote host is reportedly affected by a password disclosure vulnerability. Altiris Deployment Solution Server reportedly stores 'Application Identity Account password' in the system memory in plaintext. It may be possible for an authorized non-privileged user to retrieve this password and make unauthorized modifications to the client systems. The level of unauthorized access depends on the user group under which Application Identity Account was registered during installation.

Solution

Upgrade to version 6.9 Build 355 or higher.