6
CVSSv2

CVE-2014-9324

Published: 19/12/2014 Updated: 03/01/2017
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
VMScore: 534
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

The GenericInterface in OTRS Help Desk 3.2.x prior to 3.2.17, 3.3.x prior to 3.3.11, and 4.0.x prior to 4.0.3 allows remote authenticated users to access and modify arbitrary tickets via unspecified vectors.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

otrs otrs help desk 3.2.5

otrs otrs help desk 3.2.6

otrs otrs help desk 3.2.13

otrs otrs help desk 3.2.14

otrs otrs help desk 3.3.5

otrs otrs help desk 3.3.6

otrs otrs help desk 4.0.2

otrs otrs help desk 3.2.3

otrs otrs help desk 3.2.4

otrs otrs help desk 3.2.11

otrs otrs help desk 3.2.12

otrs otrs help desk 3.3.3

otrs otrs help desk 3.3.4

otrs otrs help desk 4.0.0

otrs otrs help desk 4.0.1

otrs otrs help desk 3.2.1

otrs otrs help desk 3.2.2

otrs otrs help desk 3.2.9

otrs otrs help desk 3.2.10

otrs otrs help desk 3.3.1

otrs otrs help desk 3.3.2

otrs otrs help desk 3.3.9

otrs otrs help desk 3.3.10

otrs otrs help desk 3.2.0

otrs otrs help desk 3.2.7

otrs otrs help desk 3.2.8

otrs otrs help desk 3.2.15

otrs otrs help desk 3.2.16

otrs otrs help desk 3.3.0

otrs otrs help desk 3.3.7

otrs otrs help desk 3.3.8

Vendor Advisories

Debian Bug report logs - #876462 otrs2: CVE-2017-14635: Code Injection / Privilege Escalation OTRS Package: src:otrs2; Maintainer for src:otrs2 is Patrick Matthäi <pmatthaei@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 22 Sep 2017 14:33:02 UTC Severity: grave Tags: security, upstream ...
Thorsten Eckel of Znuny GMBH and Remo Staeuble of InfoGuard discovered a privilege escalation vulnerability in otrs2, the Open Ticket Request System An attacker with valid OTRS credentials could access and manipulate ticket data of other users via the GenericInterface, if a ticket webservice is configured and not additionally secured For the stab ...