PT-2009-2297 · Symantec · Symantec Altiris Deployment Solution

Published

2009-06-08

·

Updated

2024-02-14

·

CVE-2008-6828

CVSS v2.0

4.3

Medium

VectorAV:L/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Symantec Altiris Deployment Solution versions 6.x before 6.9.355 SP1
Description: The issue allows local users to gain privileges and modify clients of the Deployment Solution Server because the Application Identity Account password is stored in memory in cleartext.
Recommendations: For versions 6.x before 6.9.355 SP1, update to Symantec Altiris Deployment Solution 6.9.355 SP1 or later to resolve the issue.

Fix

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2008-6828

Affected Products

Symantec Altiris Deployment Solution