Vulnerability Name: | CVE-2013-4088 (CCN-85123) | ||||||||||||||||||||||||||||||||||||||||
Assigned: | 2013-06-18 | ||||||||||||||||||||||||||||||||||||||||
Published: | 2013-06-18 | ||||||||||||||||||||||||||||||||||||||||
Updated: | 2020-02-26 | ||||||||||||||||||||||||||||||||||||||||
Summary: | Kernel/Modules/AgentTicketWatcher.pm in Open Ticket Request System (OTRS) 3.0.x before 3.0.21, 3.1.x before 3.1.17, and 3.2.x before 3.2.8 does not properly restrict tickets, which allows remote attackers with a valid agent login to read restricted tickets via a crafted URL involving the ticket split mechanism. | ||||||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 6.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
| ||||||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N) 3.0 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-200 | ||||||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||||||||||||||||||||||||||||||
References: | Source: MISC Type: Third Party Advisory http://advisories.mageia.org/MGASA-2013-0196.html Source: MISC Type: Broken Link http://archives.neohapsis.com/archives/bugtraq/2013-07/0015.html Source: MITRE Type: CNA CVE-2013-4088 Source: CCN Type: SA53851 OTRS Ticket Watch Mechanism Security Bypass Vulnerability Source: DEBIAN Type: DSA-2712 otrs2 -- privilege escalation Source: CCN Type: Security Advisory 2013-04 information disclosure Source: CCN Type: BID-60688 OTRS CVE-2013-4088 Remote Security Bypass Vulnerability Source: MISC Type: Issue Tracking, Third Party Advisory https://bugs.gentoo.org/show_bug.cgi?id=CVE-2013-4088 Source: XF Type: UNKNOWN otrs-cve20134088-ticketwatch-info-disclosure(85123) Source: MISC Type: Third Party Advisory, VDB Entry https://www.securityfocus.com/bid/60688/discuss Source: CCN Type: WhiteSource Vulnerability Database CVE-2013-4088 | ||||||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||
BACK |