Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2009-3035
Description:The web console in Symantec Altiris Notification Server 6.0.x before 6.0 SP3 R12 uses a hardcoded key that can decrypt SQL Server credentials and certain discovery credentials, and stores this key on the Notification Server machine, which allows local users to obtain sensitive information and possibly execute arbitrary code by decrypting and using these credentials.
Test IDs: 1.3.6.1.4.1.25623.1.0.800985  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2009-3035
BugTraq ID: 37953
http://www.securityfocus.com/bid/37953
http://osvdb.org/62010
http://www.securitytracker.com/id?1023521
http://secunia.com/advisories/38356
http://www.vupen.com/english/advisories/2010/0256
XForce ISS Database: symantec-ans-key-unauth-access(55952)
https://exchange.xforce.ibmcloud.com/vulnerabilities/55952




© 1998-2025 E-Soft Inc. All rights reserved.