Vulnerability Name: | CVE-2013-2625 (CCN-83287) |
Assigned: | 2013-04-02 |
Published: | 2013-04-02 |
Updated: | 2020-08-18 |
Summary: | An Access Bypass issue exists in OTRS Help Desk before 3.2.4, 3.1.14, and 3.0.19, OTRS ITSM before 3.2.3, 3.1.8, and 3.0.7, and FAQ before 2.2.3, 2.1.4, and 2.0.8. Access rights by the object linking mechanism is not verified
|
CVSS v3 Severity: | 6.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): Low Integrity (I): Low Availibility (A): None | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): None Integrity (I): Low Availibility (A): None |
|
CVSS v2 Severity: | 6.4 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N) 5.6 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N/E:H/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Authentication (Au): None | Impact Metrics: | Confidentiality (C): Partial Integrity (I): Partial Availibility (A): None | 4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Medium Athentication (Au): None
| Impact Metrics: | Confidentiality (C): None Integrity (I): Partial Availibility (A): None |
|
Vulnerability Type: | CWE-269
|
Vulnerability Consequences: | Gain Access |
References: | Source: MISC Type: Broken Link, Third Party Advisory http://archives.neohapsis.com/archives/bugtraq/2013-08/0009.html
Source: MITRE Type: CNA CVE-2013-2625
Source: MISC Type: Release Notes, Third Party Advisory http://lists.opensuse.org/opensuse-updates/2013-08/msg00027.html
Source: CCN Type: SA52969 OTRS Help Desk Object Linking Mechanism Security Bypass Vulnerability
Source: CCN Type: OTRS Web site OTRS Help Desk software - OTRS IT Service Management software - Free Open Source Help Desk - Problem Management System - Customer Interaction Software | OTRS
Source: CCN Type: Security Advisory 2013-01 OTRS Information disclosure and Data manipulation
Source: CCN Type: BID-58936 Multiple OTRS Products CVE-2013-2625 Access Bypass Vulnerability
Source: MISC Type: Third Party Advisory, VDB Entry http://www.securityfocus.com/bid/58936
Source: MISC Type: Third Party Advisory, VDB Entry https://exchange.xforce.ibmcloud.com/vulnerabilities/83287
Source: XF Type: UNKNOWN otrs-cve20132625-security-bypass(83287)
Source: MISC Type: Third Party Advisory https://security-tracker.debian.org/tracker/CVE-2013-2625
Source: CCN Type: WhiteSource Vulnerability Database CVE-2013-2625
|
Vulnerable Configuration: | Configuration 1: cpe:/a:otrs:faq:*:*:*:*:*:*:*:* (Version >= 2.0.0 and < 2.0.8)OR cpe:/a:otrs:faq:*:*:*:*:*:*:*:* (Version >= 2.1.0 and < 2.1.4)OR cpe:/a:otrs:faq:*:*:*:*:*:*:*:* (Version >= 2.2.0 and < 2.2.3)OR cpe:/a:otrs:otrs_help_desk:*:*:*:*:*:*:*:* (Version >= 3.0.0 and < 3.0.19)OR cpe:/a:otrs:otrs_help_desk:*:*:*:*:*:*:*:* (Version >= 3.1.0 and < 3.1.14)OR cpe:/a:otrs:otrs_help_desk:*:*:*:*:*:*:*:* (Version > 3.2.0 and < 3.2.4)OR cpe:/a:otrs:otrs_itsm:*:*:*:*:*:*:*:* (Version >= 3.0.0 and < 3.0.7)OR cpe:/a:otrs:otrs_itsm:*:*:*:*:*:*:*:* (Version >= 3.1.0 and < 3.1.8)OR cpe:/a:otrs:otrs_itsm:*:*:*:*:*:*:*:* (Version >= 3.2.0 and < 3.2.3) Configuration 2: cpe:/o:debian:debian_linux:8.0:*:*:*:*:*:*:*OR cpe:/o:debian:debian_linux:9.0:*:*:*:*:*:*:*OR cpe:/o:debian:debian_linux:10.0:*:*:*:*:*:*:* Configuration 3: cpe:/o:opensuse:opensuse:12.2:*:*:*:*:*:*:*OR cpe:/o:opensuse:opensuse:12.3:*:*:*:*:*:*:* Configuration CCN 1: cpe:/a:otrs:otrs_help_desk:3.2.3:*:*:*:*:*:*:*OR cpe:/a:otrs:otrs_itsm:3.2.2:*:*:*:*:*:*:*OR cpe:/a:otrs:otrs_itsm:3.1.7:*:*:*:*:*:*:*OR cpe:/a:otrs:otrs_itsm:3.0.6:*:*:*:*:*:*:*OR cpe:/a:otrs:faq:2.2.2:*:*:*:*:*:*:*OR cpe:/a:otrs:faq:2.1.3:*:*:*:*:*:*:*OR cpe:/a:otrs:faq:2.0.7:*:*:*:*:*:*:*
Denotes that component is vulnerable |
Oval Definitions |
|
BACK |