Novell ZENWorks Asset Management Information Disclosure Vulnerabilities

Summary
This host is running Novell ZENWorks Asset Management and is prone to information disclosure vulnerabilities.
Impact
Successful exploitation will allow remote attackers to obtain sensitive information via a crafted rtrlet/rtr request for the HandleMaintenanceCalls function. Impact Level: Application
Solution
Apply the patch from the below link or update to latest version, For patch refer to http://download.novell.com/Download?buildid=yse-osBjxeo~ For updates refer to http://www.novell.com/products/zenworks/assetmanagement ***** NOTE: Ignore this warning if above mentioned patch is installed. *****
Insight
The 'GetFile_Password()' and 'GetConfigInfo_Password()' method within the rtrlet component contains hard coded credentials and can be exploited to gain access to the configuration file and download arbitrary files by specifying an absolute path.
Affected
Novell ZENworks Asset Management version 7.5
References