Vulnerability Description
An Access Bypass issue exists in OTRS Help Desk before 3.2.4, 3.1.14, and 3.0.19, OTRS ITSM before 3.2.3, 3.1.8, and 3.0.7, and FAQ before 2.2.3, 2.1.4, and 2.0.8. Access rights by the object linking mechanism is not verified
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Otrs | Faq | >= 2.0.0, < 2.0.8 |
| Otrs | Otrs Help Desk | >= 3.0.0, < 3.0.19 |
| Otrs | Otrs Itsm | >= 3.0.0, < 3.0.7 |
| Debian | Debian Linux | 8.0 |
| Opensuse | Opensuse | 12.2 |
Related Weaknesses (CWE)
References
- http://archives.neohapsis.com/archives/bugtraq/2013-08/0009.htmlBroken LinkThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-08/msg00027.htmlRelease NotesThird Party Advisory
- http://www.securityfocus.com/bid/58936Third Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/83287Third Party AdvisoryVDB Entry
- https://security-tracker.debian.org/tracker/CVE-2013-2625Third Party Advisory
- http://archives.neohapsis.com/archives/bugtraq/2013-08/0009.htmlBroken LinkThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-08/msg00027.htmlRelease NotesThird Party Advisory
- http://www.securityfocus.com/bid/58936Third Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/83287Third Party AdvisoryVDB Entry
- https://security-tracker.debian.org/tracker/CVE-2013-2625Third Party Advisory
FAQ
What is CVE-2013-2625?
CVE-2013-2625 is a vulnerability with a CVSS score of 6.5 (MEDIUM). An Access Bypass issue exists in OTRS Help Desk before 3.2.4, 3.1.14, and 3.0.19, OTRS ITSM before 3.2.3, 3.1.8, and 3.0.7, and FAQ before 2.2.3, 2.1.4, and 2.0.8. Access rights by the object linking ...
How severe is CVE-2013-2625?
CVE-2013-2625 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-2625?
Check the references section above for vendor advisories and patch information. Affected products include: Otrs Faq, Otrs Otrs Help Desk, Otrs Otrs Itsm, Debian Debian Linux, Opensuse Opensuse.