| Vulnerability Name: | CVE-2013-2625 (CCN-83287) | ||||||||||||||||||||||||||||||||||||
| Assigned: | 2013-04-02 | ||||||||||||||||||||||||||||||||||||
| Published: | 2013-04-02 | ||||||||||||||||||||||||||||||||||||
| Updated: | 2020-08-18 | ||||||||||||||||||||||||||||||||||||
| Summary: | An Access Bypass issue exists in OTRS Help Desk before 3.2.4, 3.1.14, and 3.0.19, OTRS ITSM before 3.2.3, 3.1.8, and 3.0.7, and FAQ before 2.2.3, 2.1.4, and 2.0.8. Access rights by the object linking mechanism is not verified | ||||||||||||||||||||||||||||||||||||
| CVSS v3 Severity: | 6.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
| ||||||||||||||||||||||||||||||||||||
| CVSS v2 Severity: | 6.4 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N) 5.6 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N/E:H/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||||||||||||||||||||||||||||||
| Vulnerability Type: | CWE-269 | ||||||||||||||||||||||||||||||||||||
| Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||||||||||||||
| References: | Source: MISC Type: Broken Link, Third Party Advisory http://archives.neohapsis.com/archives/bugtraq/2013-08/0009.html Source: MITRE Type: CNA CVE-2013-2625 Source: MISC Type: Release Notes, Third Party Advisory http://lists.opensuse.org/opensuse-updates/2013-08/msg00027.html Source: CCN Type: SA52969 OTRS Help Desk Object Linking Mechanism Security Bypass Vulnerability Source: CCN Type: OTRS Web site OTRS Help Desk software - OTRS IT Service Management software - Free Open Source Help Desk - Problem Management System - Customer Interaction Software | OTRS Source: CCN Type: Security Advisory 2013-01 OTRS Information disclosure and Data manipulation Source: CCN Type: BID-58936 Multiple OTRS Products CVE-2013-2625 Access Bypass Vulnerability Source: MISC Type: Third Party Advisory, VDB Entry http://www.securityfocus.com/bid/58936 Source: MISC Type: Third Party Advisory, VDB Entry https://exchange.xforce.ibmcloud.com/vulnerabilities/83287 Source: XF Type: UNKNOWN otrs-cve20132625-security-bypass(83287) Source: MISC Type: Third Party Advisory https://security-tracker.debian.org/tracker/CVE-2013-2625 Source: CCN Type: WhiteSource Vulnerability Database CVE-2013-2625 | ||||||||||||||||||||||||||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||||||||||||||
| Oval Definitions | |||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||
| BACK | |||||||||||||||||||||||||||||||||||||