6.5

CVE-2013-2625

An Access Bypass issue exists in OTRS Help Desk before 3.2.4, 3.1.14, and 3.0.19, OTRS ITSM before 3.2.3, 3.1.8, and 3.0.7, and FAQ before 2.2.3, 2.1.4, and 2.0.8. Access rights by the object linking mechanism is not verified
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Otrs ≫ Faq Version >= 2.0.0 < 2.0.8
Otrs ≫ Faq Version >= 2.1.0 < 2.1.4
Otrs ≫ Faq Version >= 2.2.0 < 2.2.3
Otrs ≫ Otrs Help Desk Version >= 3.0.0 < 3.0.19
Otrs ≫ Otrs Help Desk Version >= 3.1.0 < 3.1.14
Otrs ≫ Otrs Help Desk Version > 3.2.0 < 3.2.4
Otrs ≫ Otrs Itsm Version >= 3.0.0 < 3.0.7
Otrs ≫ Otrs Itsm Version >= 3.1.0 < 3.1.8
Otrs ≫ Otrs Itsm Version >= 3.2.0 < 3.2.3
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Opensuse ≫ Opensuse Version 12.2
Opensuse ≫ Opensuse Version 12.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.29% 0.665
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 3.9 2.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
NIST 6.4 10 4.9
AV:N/AC:L/Au:N/C:P/I:P/A:N
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

http://archives.neohapsis.com/archives/bugtraq/2013-08/0009.html
Third Party Advisory
Broken Link
http://lists.opensuse.org/opensuse-updates/2013-08/msg00027.html
Third Party Advisory
Release Notes
http://www.securityfocus.com/bid/58936
Third Party Advisory
VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/83287
Third Party Advisory
VDB Entry
https://security-tracker.debian.org/tracker/CVE-2013-2625
Third Party Advisory