FastPatch for (a) PatchLink Update Server (PLUS) before 6.1 P1 and 6.2.x before 6.2 SR1 P1, and (b) Novell ZENworks 6.2 SR1 and earlier, does not require authentication for dagent/proxyreg.asp, which allows remote attackers to list, add, or delete PatchLink Distribution Point (PDP) proxy servers via modified (1) List, (2) Proxy, or (3) Delete parameters.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Patchlink_update_server | Lumension | 6.1 (including) | 6.1 (including) |
Patchlink_update_server | Lumension | 6.2.0.181 (including) | 6.2.0.181 (including) |
Patchlink_update_server | Lumension | 6.2.0.189 (including) | 6.2.0.189 (including) |
Zenworks | Novell | * | 6.2 (including) |