CVE-2011-2746

OTRS <2.4.11, <3.0.10 - Info Disclosure

Title source: llm
STIX 2.1

Description

Unspecified vulnerability in Kernel/Modules/AdminPackageManager.pm in OTRS-Core in Open Ticket Request System (OTRS) 2.x before 2.4.11 and 3.x before 3.0.10 allows remote authenticated administrators to read arbitrary files via unknown vectors.

References (6)

Core 6
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/45894
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/49251
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/74602
Mailing List vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2011-09/msg00011.html
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/45701
Vendor Advisory x_refsource_confirm
http://otrs.org/advisory/OSA-2011-03-en/

Scores

EPSS 0.0174
EPSS Percentile 75.1%

Details

Status published
Products (34)
otrs/otrs 2.0.0 (6 CPE variants)
otrs/otrs 2.0.1
otrs/otrs 2.0.2
otrs/otrs 2.0.3
otrs/otrs 2.0.4
otrs/otrs 2.0.5
otrs/otrs 2.1.0 beta1 (2 CPE variants)
otrs/otrs 2.1.1
otrs/otrs 2.1.2
otrs/otrs 2.1.3
... and 24 more
Published Aug 29, 2011
Tracked Since Feb 18, 2026