CVE-2011-2385
Summary
| CVE | CVE-2011-2385 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-07-19 20:55:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The iPhoneHandle package 0.9.x before 0.9.7 and 1.0.x before 1.0.3 in Open Ticket Request System (OTRS) does not properly restrict use of the iPhoneHandle interface, which allows remote authenticated users to gain privileges, and consequently read or modify OTRS core objects, via unspecified vectors. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:S/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Otrs | Iphonehandle | 0.9.1 | All | All | All |
| Application | Otrs | Iphonehandle | 0.9.2 | All | All | All |
| Application | Otrs | Iphonehandle | 0.9.3 | All | All | All |
| Application | Otrs | Iphonehandle | 0.9.4 | All | All | All |
| Application | Otrs | Iphonehandle | 0.9.5 | All | All | All |
| Application | Otrs | Iphonehandle | 0.9.6 | All | All | All |
| Application | Otrs | Iphonehandle | 1.0.1 | All | All | All |
| Application | Otrs | Iphonehandle | 1.0.2 | All | All | All |
| Application | Otrs | Otrs | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| OTRS iPhoneHandle Package Privilege Escalation Vulnerability - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| osvdb.org/73885 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Official Site of OTRS, a leading service management solution | af854a3a-2127-422b-91ae-364da2661108 | otrs.org | Patch, Vendor Advisory |
| OTRS iPhoneHandle (CVE-2011-2385) Unspecified Privilege Escalation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.