Логотип exploitDog
bind:CVE-2009-5055
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2009-5055

Количество 4

Количество 4

ubuntu логотип

CVE-2009-5055

почти 15 лет назад

Open Ticket Request System (OTRS) before 2.4.4 grants ticket access on the basis of single-digit substrings of the CustomerID value, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by visiting a ticket, as demonstrated by leveraging the CustomerID 12 account to read tickets that should be available only to CustomerID 1 or CustomerID 2.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2009-5055

почти 15 лет назад

Open Ticket Request System (OTRS) before 2.4.4 grants ticket access on the basis of single-digit substrings of the CustomerID value, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by visiting a ticket, as demonstrated by leveraging the CustomerID 12 account to read tickets that should be available only to CustomerID 1 or CustomerID 2.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2009-5055

почти 15 лет назад

Open Ticket Request System (OTRS) before 2.4.4 grants ticket access on ...

CVSS2: 3.5
EPSS: Низкий
github логотип

GHSA-mc47-5crj-3q7q

больше 3 лет назад

Open Ticket Request System (OTRS) before 2.4.4 grants ticket access on the basis of single-digit substrings of the CustomerID value, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by visiting a ticket, as demonstrated by leveraging the CustomerID 12 account to read tickets that should be available only to CustomerID 1 or CustomerID 2.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2009-5055

Open Ticket Request System (OTRS) before 2.4.4 grants ticket access on the basis of single-digit substrings of the CustomerID value, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by visiting a ticket, as demonstrated by leveraging the CustomerID 12 account to read tickets that should be available only to CustomerID 1 or CustomerID 2.

CVSS2: 3.5
0%
Низкий
почти 15 лет назад
nvd логотип
CVE-2009-5055

Open Ticket Request System (OTRS) before 2.4.4 grants ticket access on the basis of single-digit substrings of the CustomerID value, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by visiting a ticket, as demonstrated by leveraging the CustomerID 12 account to read tickets that should be available only to CustomerID 1 or CustomerID 2.

CVSS2: 3.5
0%
Низкий
почти 15 лет назад
debian логотип
CVE-2009-5055

Open Ticket Request System (OTRS) before 2.4.4 grants ticket access on ...

CVSS2: 3.5
0%
Низкий
почти 15 лет назад
github логотип
GHSA-mc47-5crj-3q7q

Open Ticket Request System (OTRS) before 2.4.4 grants ticket access on the basis of single-digit substrings of the CustomerID value, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by visiting a ticket, as demonstrated by leveraging the CustomerID 12 account to read tickets that should be available only to CustomerID 1 or CustomerID 2.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу