LOW · 3.5

CVE-2009-5055

Open Ticket Request System (OTRS) before 2.4.4 grants ticket access on the basis of single-digit substrings of the CustomerID value, which allows remote authenticated users to bypass intended access r...

Vulnerability Description

Open Ticket Request System (OTRS) before 2.4.4 grants ticket access on the basis of single-digit substrings of the CustomerID value, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by visiting a ticket, as demonstrated by leveraging the CustomerID 12 account to read tickets that should be available only to CustomerID 1 or CustomerID 2.

CVSS Score

3.5

LOW

AV:N/AC:M/Au:S/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
OtrsOtrs<= 2.4.3

Related Weaknesses (CWE)

References

FAQ

What is CVE-2009-5055?

CVE-2009-5055 is a vulnerability with a CVSS score of 3.5 (LOW). Open Ticket Request System (OTRS) before 2.4.4 grants ticket access on the basis of single-digit substrings of the CustomerID value, which allows remote authenticated users to bypass intended access r...

How severe is CVE-2009-5055?

CVE-2009-5055 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2009-5055?

Check the references section above for vendor advisories and patch information. Affected products include: Otrs Otrs.