It was found that openwsman can access various secret files without having the correct privileges set. A local attacker could use this for information disclosure.
Openwsman, versions up to and including 2.6.9, are vulnerable to infinite loop in processconnection() when parsing specially crafted HTTP requests. A remote, unauthenticated attacker can exploit this vulnerability by sending malicious HTTP request to cause denial of service to openwsman server.