Request Tracker CVE-2013-3369 Security Bypass Vulnerability
BID:60094
Info
Request Tracker CVE-2013-3369 Security Bypass Vulnerability
| Bugtraq ID: | 60094 |
| Class: | Access Validation Error |
| CVE: |
CVE-2013-3369 |
| Remote: | Yes |
| Local: | No |
| Published: | May 22 2013 12:00AM |
| Updated: | May 22 2013 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 Bestpractical RT 3.8.16 Bestpractical RT 3.8.15 Bestpractical RT 3.8.11 Bestpractical RT 3.8.10 Bestpractical RT 3.8.8 Bestpractical RT 3.8.6 Bestpractical RT 3.8.5 Bestpractical RT 3.8.4 Bestpractical RT 3.8.2 Bestpractical RT 4.0.8 Bestpractical RT 4.0.6 Bestpractical RT 4.0.12 Bestpractical RT 4.0.10 Bestpractical RT 4.0 Bestpractical RT 3.8.9 Bestpractical RT 3.8.12 Bestpractical RT 3.8 |
| Not Vulnerable: |
Bestpractical RT 3.8.17 Bestpractical RT 4.0.13 |
Discussion
Request Tracker CVE-2013-3369 Security Bypass Vulnerability
Request Tracker is prone to a security-bypass vulnerability.
An attacker may exploit this issue to bypass certain security restrictions and perform unauthorized actions. This may aid in further attacks.
The following versions are vulnerable:
Request Tracker 3.8.x prior to 3.8.17
Request Tracker 4.0.x prior to 4.0.13
Request Tracker is prone to a security-bypass vulnerability.
An attacker may exploit this issue to bypass certain security restrictions and perform unauthorized actions. This may aid in further attacks.
The following versions are vulnerable:
Request Tracker 3.8.x prior to 3.8.17
Request Tracker 4.0.x prior to 4.0.13
Solution / Fix
Request Tracker CVE-2013-3369 Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.