CVE-2022-40816

MEDIUM

Zammad 5.2.1 - Incorrect Access Control

Title source: llm
STIX 2.1

Description

Zammad 5.2.1 is vulnerable to Incorrect Access Control. Zammad's asset handling mechanism has logic to ensure that customer users are not able to see personal information of other users. This logic was not effective when used through a web socket connection, so that a logged-in attacker would be able to fetch personal data of other users by querying the Zammad API. This issue is fixed in , 5.2.2.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_misc
https://zammad.com/de/advisories/zaa-2022-09

Scores

CVSS v3 6.5
EPSS 0.0065
EPSS Percentile 46.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (1)
zammad/zammad 5.2.0 - 5.2.2
Published Sep 27, 2022
Tracked Since Feb 18, 2026