OTRS SOAP Interface Security Bypass Vulnerability
BID:28647
Info
OTRS SOAP Interface Security Bypass Vulnerability
| Bugtraq ID: | 28647 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-1515 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 31 2008 12:00AM |
| Updated: | Apr 18 2008 12:29AM |
| Credit: | OTRS |
| Vulnerable: |
S.u.S.E. openSUSE 10.3 S.u.S.E. openSUSE 10.2 Redhat Fedora 7 OTRS OTRS 2.2.5 OTRS OTRS 2.2 OTRS OTRS 2.1.7 OTRS OTRS 2.1 |
| Not Vulnerable: |
OTRS OTRS 2.2.6 OTRS OTRS 2.1.8 |
Discussion
OTRS SOAP Interface Security Bypass Vulnerability
OTRS is prone to a security-bypass vulnerability because it fails to properly validate user credentials before performing certain actions.
Successful exploits will allow attackers to bypass certain security restrictions and to read and modify objects through the OTRS SOAP interface.
This issue affects these versions:
OTRS 2.1.x prior to 2.1.8
OTRS 2.2.x prior to 2.2.6
OTRS is prone to a security-bypass vulnerability because it fails to properly validate user credentials before performing certain actions.
Successful exploits will allow attackers to bypass certain security restrictions and to read and modify objects through the OTRS SOAP interface.
This issue affects these versions:
OTRS 2.1.x prior to 2.1.8
OTRS 2.2.x prior to 2.2.6
Exploit / POC
OTRS SOAP Interface Security Bypass Vulnerability
An attacker can exploit this issue using standard tools.
An attacker can exploit this issue using standard tools.
Solution / Fix
OTRS SOAP Interface Security Bypass Vulnerability
Solution:
The vendor has released an advisory and updates. Please see the references for more information.
Solution:
The vendor has released an advisory and updates. Please see the references for more information.
References
OTRS SOAP Interface Security Bypass Vulnerability
References:
References:
- OTRS Homepage (OTRS)
- OTRS Security Advisory 2008-01 (OTRS)