Openwsman, versions up to and including 2.6.9, are vulnerable to infinite loop in processconnection() when parsing specially crafted HTTP requests. A remote, unauthenticated attacker can exploit this vulnerability by sending malicious HTTP request to cause denial of service to openwsman server.
It was found that openwsman can access various secret files without having the correct privileges set. A local attacker could use this for information disclosure.