Описание
The SOAP interface in OTRS 2.1.x before 2.1.8 and 2.2.x before 2.2.6 allows remote attackers to "read and modify objects" via SOAP requests, related to "Missing security checks."
Ссылки
- Third Party Advisory
- Vendor Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Third Party Advisory
- Third Party Advisory
- Vendor Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 2.1.0 (включая) до 2.1.8 (исключая)Версия от 2.2.0 (включая) до 2.2.6 (исключая)
Одно из
cpe:2.3:a:otrs:otrs:*:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:*:*:*:*:*:*:*:*
EPSS
Процентиль: 71%
0.00709
Низкий
6.4 Medium
CVSS2
Дефекты
CWE-264
Связанные уязвимости
ubuntu
больше 17 лет назад
The SOAP interface in OTRS 2.1.x before 2.1.8 and 2.2.x before 2.2.6 allows remote attackers to "read and modify objects" via SOAP requests, related to "Missing security checks."
debian
больше 17 лет назад
The SOAP interface in OTRS 2.1.x before 2.1.8 and 2.2.x before 2.2.6 a ...
github
больше 3 лет назад
The SOAP interface in OTRS 2.1.x before 2.1.8 and 2.2.x before 2.2.6 allows remote attackers to "read and modify objects" via SOAP requests, related to "Missing security checks."
EPSS
Процентиль: 71%
0.00709
Низкий
6.4 Medium
CVSS2
Дефекты
CWE-264