CVE-2004-2622
UnknownEPSS 2.60%
Last modified
CVE-2004-2622 is a vulnerability of currently unknown severity. AClient.exe in Altiris Deployment Solution 6.x and 5.x does not require authentication from the first Deployment Server that it connects to, which allows remote malicious servers to gain administrator access.. EPSS estimates a 2.60% chance of exploitation in the next 30 days.
Description
AClient.exe in Altiris Deployment Solution 6.x and 5.x does not require authentication from the first Deployment Server that it connects to, which allows remote malicious servers to gain administrator access.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Altiris | Deployment Server Extension For Ibm Director | 5.0.1 |
| Altiris | Deployment Server Extension For Ibm Director | 5.5 |
| Altiris | Deployment Server Extension For Ibm Director | 6.0 |
| Altiris | Deployment Server Extension For Ibm Director | 6.1 |
References
- http://secunia.com/advisories/12944Vendor Advisory
- http://securitytracker.com/id?1011862Vendor Advisory
- http://secunia.com/advisories/12944Vendor Advisory
- http://securitytracker.com/id?1011862Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-2622?
AClient.exe in Altiris Deployment Solution 6.x and 5.x does not require authentication from the first Deployment Server that it connects to, which allows remote malicious servers to gain administrator access.
How severe is CVE-2004-2622?
Severity scoring for CVE-2004-2622 is pending analysis. The EPSS model estimates a 2.60% probability of exploitation in the next 30 days.
How do I fix CVE-2004-2622?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2004
- CVE-2004-2616The file server in ActivePost Standard 3.1 and earlier allow…
- CVE-2004-2617Directory traversal vulnerability in Pegasi Web Server (PWS)…
- CVE-2004-2618Cross-site scripting (XSS) vulnerability in Pegasi Web Serve…
- CVE-2004-2619ripMIME 1.3.2.3 and earlier allows remote attackers to bypas…
- CVE-2004-2620The MIMEH_read_headers function in ripMIME 1.3.1.0 does not …
- CVE-2004-2621Nortel Contivity VPN Client 2.1.7, 3.00, 3.01, 4.91, and 5.0…
- CVE-2004-2623Unknown vulnerability in Rippy the Aggregator before 0.10, w…
- CVE-2004-2624Cross-site scripting (XSS) vulnerability in "TextSearch" in …
- CVE-2004-2625Cross-site scripting (XSS) vulnerability in Outblaze Email a…
- CVE-2004-2626GUI overlay vulnerability in the Java API in Siemens S55 cel…
- CVE-2004-2627Java 2 Micro Edition (J2ME) does not properly validate bytec…
- CVE-2004-2628Multiple directory traversal vulnerabilities in thttpd 2.07 …
Are you affected by CVE-2004-2622?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
