BMC BladeLogic Server Automation (BSA) before 8.7 Patch 3 allows remote attackers to bypass authentication and consequently read arbitrary files or possibly have unspecified other impact by leveraging a "logic flaw" in the authentication process.
http://www.securityfocus.com/bid/92736
http://www.securityfocus.com/archive/1/539351/100/0/threaded