cbcvebase.
CVE-2012-4933
published 2012-10-20

CVE-2012-4933: The rtrlet web application in the Web Console in Novell ZENworks Asset Management (ZAM) 7.5 uses a hard-coded username of Ivanhoe and a hard-coded password of…

PriorityP260high7.8CVSS 2.0
AVNACLAuNCCINAN
EXPLOIT
EPSS
44.01%
98.6th percentile
The rtrlet web application in the Web Console in Novell ZENworks Asset Management (ZAM) 7.5 uses a hard-coded username of Ivanhoe and a hard-coded password of Scott for the (1) GetFile_Password and (2) GetConfigInfo_Password operations, which allows remote attackers to obtain sensitive information via a crafted rtrlet/rtr request for the HandleMaintenanceCalls function.

Affected

1 ranges
VendorProductVersion rangeFixed in
novellzenworks_asset_management

Detection & IOCsextracted from sources · hover to see the quote

urlrtrlet/rtr
commandusername: Ivanhoe, password: Scott
  • Detect unauthenticated requests to the rtrlet/rtr endpoint targeting the HandleMaintenanceCalls function, particularly for GetFile_Password or GetConfigInfo_Password operations
  • Alert on HTTP requests to the rtrlet component of Novell ZENworks Asset Management Web Console that include hardcoded credential usage (Ivanhoe/Scott) for GetConfig or GetFile maintenance tasks
  • Monitor for unauthenticated retrieval of configuration parameters (including database credentials in clear text) via the rtrlet component
  • Alert on unauthenticated remote file access attempts via the rtrlet component, particularly large file retrievals up to 100,000,000 KB
  • ·The hardcoded credentials (Ivanhoe/Scott) are baked into the application and cannot be changed by configuration — exploitation requires no prior authentication
  • ·Vulnerability is specific to Novell ZENworks Asset Management version 7.5 Web Console; the rtrlet web application is the affected component
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.