Altiris Deployment Solution Server < 6.9.355 Password Disclosure (SYM08-020) (deprecated)
Medium Nessus Network Monitor Plugin ID 4772
SynopsisThe remote Windows host has a program that is affected by a password disclosure vulnerability.
DescriptionThe version of the Altiris Deployment Solution installed on the remote host is reportedly affected by a password disclosure vulnerability. Altiris Deployment Solution Server reportedly stores 'Application Identity Account password' in the system memory in plaintext. It may be possible for an authorized non-privileged user to retrieve this password and make unauthorized modifications to the client systems. The level of unauthorized access depends on the user group under which Application Identity Account was registered during installation.
SolutionUpgrade to version 6.9 Build 355 or higher.