Vulnerability Description
The SOAP interface in OTRS 2.1.x before 2.1.8 and 2.2.x before 2.2.6 allows remote attackers to "read and modify objects" via SOAP requests, related to "Missing security checks."
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Otrs | Otrs | >= 2.1.0, < 2.1.8 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00005.htmlThird Party Advisory
- http://otrs.org/advisory/OSA-2008-01-en/Vendor Advisory
- http://secunia.com/advisories/29585Third Party Advisory
- http://secunia.com/advisories/29622Third Party Advisory
- http://secunia.com/advisories/29859Third Party Advisory
- http://www.securityfocus.com/bid/28647Third Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41577Third Party AdvisoryVDB Entry
- https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00284.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00005.htmlThird Party Advisory
- http://otrs.org/advisory/OSA-2008-01-en/Vendor Advisory
- http://secunia.com/advisories/29585Third Party Advisory
- http://secunia.com/advisories/29622Third Party Advisory
- http://secunia.com/advisories/29859Third Party Advisory
- http://www.securityfocus.com/bid/28647Third Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41577Third Party AdvisoryVDB Entry
FAQ
What is CVE-2008-1515?
CVE-2008-1515 is a vulnerability with a CVSS score of 6.4 (MEDIUM). The SOAP interface in OTRS 2.1.x before 2.1.8 and 2.2.x before 2.2.6 allows remote attackers to "read and modify objects" via SOAP requests, related to "Missing security checks."
How severe is CVE-2008-1515?
CVE-2008-1515 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-1515?
Check the references section above for vendor advisories and patch information. Affected products include: Otrs Otrs.