CVE-2011-2385Iphonehandle vulnerability

CWE-2643 documents3 sources
Severity
6.5MEDIUMNVD
EPSS
0.7%
top 27.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 19
Latest updateMay 17

Description

The iPhoneHandle package 0.9.x before 0.9.7 and 1.0.x before 1.0.3 in Open Ticket Request System (OTRS) does not properly restrict use of the iPhoneHandle interface, which allows remote authenticated users to gain privileges, and consequently read or modify OTRS core objects, via unspecified vectors.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 8.0 | Impact: 6.4

Affected Packages2 packages

NVDotrs/iphonehandle8 versions+7
debiandebian/otrs2

Patches

🔴Vulnerability Details

1
GHSA
GHSA-6qwj-3rxx-5p34: The iPhoneHandle package 02022-05-17

📋Vendor Advisories

1
Debian
CVE-2011-2385: otrs2 - The iPhoneHandle package 0.9.x before 0.9.7 and 1.0.x before 1.0.3 in Open Ticke...2011