Unicenter Asset Manager uses a weak encryption algorithm to store passwords. A local attacker that has access to configuration files could obtain the encrypted passwords and trivially decrypt them.
Classification
Unknown or Incomplete
Solution
Currently, there are no known workarounds or upgrades to correct this issue. However, Computer Associates has released three patches to address this vulnerability.
CONSOLE (QO39700), SETUP (QO39704) and ENGINE (QO39702)