FastPatch for (a) PatchLink Update Server (PLUS) before 6.1 P1 and 6.2.x before 6.2 SR1 P1, and (b) Novell ZENworks 6.2 SR1 and earlier, does not require authentication for dagent/proxyreg.asp, which allows remote attackers to list, add, or delete PatchLink Distribution Point (PDP) proxy servers via modified (1) List, (2) Proxy, or (3) Delete parameters.
| Software | From | Fixed in |
|---|---|---|
| novell / zenworks | - | 6.2.x |
| lumension / patchlink_update_server | 6.2.0.181 | 6.2.0.181.x |
| lumension / patchlink_update_server | 6.1 | 6.1.x |
| lumension / patchlink_update_server | 6.2.0.189 | 6.2.0.189.x |