CVE-2015-1464Improper Access Control in Request-tracker4

Severity
6.4MEDIUMNVD
EPSS
0.3%
top 42.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 9
Latest updateMay 17

Description

RT (aka Request Tracker) before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to hijack sessions via an RSS feed URL.

CVSS vector

AV:N/AC:L/C:P/I:P/A:NExploitability: 10.0 | Impact: 4.9

Affected Packages2 packages

debiandebian/request-tracker4< request-tracker4 4.2.8-3 (bookworm)

Also affects: Fedora 21, 22

🔴Vulnerability Details

2
GHSA
GHSA-g28c-mrpm-x2wh: RT (aka Request Tracker) before 42022-05-17
OSV
CVE-2015-1464: RT (aka Request Tracker) before 42015-03-09

📋Vendor Advisories

1
Debian
CVE-2015-1464: request-tracker4 - RT (aka Request Tracker) before 4.0.23 and 4.2.x before 4.2.10 allows remote att...2015

💬Community

3
Bugzilla
CVE-2015-5348 Camel: Java object deserialisation in Jetty/Servlet2015-12-18
Bugzilla
CVE-2015-1464 rt: session hijaking flaw in RSS feed handler2015-03-09
Bugzilla
CVE-2015-1464 rt: session hijaking flaw in RSS feed handler [fedora-21]2015-03-09
CVE-2015-1464 — Improper Access Control | cvebase