CVE-2013-2625

MEDIUM

OTRS Help Desk <3.2.4-3.0.19 - Auth Bypass

Title source: llm
STIX 2.1

Description

An Access Bypass issue exists in OTRS Help Desk before 3.2.4, 3.1.14, and 3.0.19, OTRS ITSM before 3.2.3, 3.1.8, and 3.0.7, and FAQ before 2.2.3, 2.1.4, and 2.0.8. Access rights by the object linking mechanism is not verified

References (5)

Core 5
Core References
Third Party Advisory x_refsource_misc
https://security-tracker.debian.org/tracker/CVE-2013-2625
Release Notes, Third Party Advisory x_refsource_misc
http://lists.opensuse.org/opensuse-updates/2013-08/msg00027.html
Broken Link, Third Party Advisory x_refsource_misc
http://archives.neohapsis.com/archives/bugtraq/2013-08/0009.html
Third Party Advisory, VDB Entry x_refsource_misc
http://www.securityfocus.com/bid/58936
Third Party Advisory, VDB Entry x_refsource_misc
https://exchange.xforce.ibmcloud.com/vulnerabilities/83287

Scores

CVSS v3 6.5
EPSS 0.0129
EPSS Percentile 66.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Details

CWE
CWE-269
Status published
Products (8)
debian/debian_linux 8.0
debian/debian_linux 9.0
debian/debian_linux 10.0
opensuse/opensuse 12.2
opensuse/opensuse 12.3
otrs/faq 2.0.0 - 2.0.8
otrs/otrs_help_desk 3.0.0 - 3.0.19
otrs/otrs_itsm 3.0.0 - 3.0.7
Published Nov 27, 2019
Tracked Since Feb 18, 2026