Debian Otrs2 vulnerabilities

113 known vulnerabilities affecting debian/otrs2.

Total CVEs
113
CISA KEV
1
actively exploited
Public exploits
9
Exploited in wild
3
Severity breakdown
HIGH11MEDIUM56LOW46

Vulnerabilities

Page 6 of 6
CVE-2008-7281MEDIUMCVSS 4.3fixed in otrs2 2.2.7-1 (bullseye)2008
CVE-2008-7281 [MEDIUM] CVE-2008-7281: otrs2 - Open Ticket Request System (OTRS) before 2.2.7 sends e-mail containing a Bcc hea... Open Ticket Request System (OTRS) before 2.2.7 sends e-mail containing a Bcc header field that lists the Blind Carbon Copy recipients, which allows remote attackers to obtain potentially sensitive e-mail address information by reading this field. Scope: local bullseye: resolved (fixed in 2.2.7-1)
debian
CVE-2008-7283MEDIUMCVSS 6.0fixed in otrs2 2.2.6-1 (bullseye)2008
CVE-2008-7283 [MEDIUM] CVE-2008-7283: otrs2 - Open Ticket Request System (OTRS) before 2.2.6, when customer group support is e... Open Ticket Request System (OTRS) before 2.2.6, when customer group support is enabled, allows remote authenticated users to bypass intended access restrictions and perform web-interface updates to tickets by leveraging queue read permissions. Scope: local bullseye: resolved (fixed in 2.2.6-1)
debian
CVE-2008-7282MEDIUMCVSS 4.6fixed in otrs2 2.2.6-1 (bullseye)2008
CVE-2008-7282 [MEDIUM] CVE-2008-7282: otrs2 - Kernel/Output/HTML/CustomerNewTicketQueueSelectionGeneric.pm in Open Ticket Requ... Kernel/Output/HTML/CustomerNewTicketQueueSelectionGeneric.pm in Open Ticket Request System (OTRS) before 2.2.6, when the CustomerPanelOwnSelection and CustomerGroupSupport options are enabled, allows remote authenticated users to bypass intended access restrictions, and perform certain (1) list and (2) write operations on queues, via unspecified vectors. Scope: local
debian
CVE-2008-1515MEDIUMCVSS 6.4fixed in otrs2 2.2.5-2 (bullseye)2008
CVE-2008-1515 [MEDIUM] CVE-2008-1515: otrs2 - The SOAP interface in OTRS 2.1.x before 2.1.8 and 2.2.x before 2.2.6 allows remo... The SOAP interface in OTRS 2.1.x before 2.1.8 and 2.2.x before 2.2.6 allows remote attackers to "read and modify objects" via SOAP requests, related to "Missing security checks." Scope: local bullseye: resolved (fixed in 2.2.5-2)
debian
CVE-2008-7280MEDIUMCVSS 5.0fixed in otrs2 2.2.7-1 (bullseye)2008
CVE-2008-7280 [MEDIUM] CVE-2008-7280: otrs2 - Kernel/System/EmailParser.pm in PostmasterPOP3.pl in Open Ticket Request System ... Kernel/System/EmailParser.pm in PostmasterPOP3.pl in Open Ticket Request System (OTRS) before 2.2.7 does not properly handle e-mail messages containing malformed UTF-8 characters, which allows remote attackers to cause a denial of service (e-mail retrieval outage) via a crafted message. Scope: local bullseye: resolved (fixed in 2.2.7-1)
debian
CVE-2008-7279MEDIUMCVSS 6.5fixed in otrs2 2.3.2-1 (bullseye)2008
CVE-2008-7279 [MEDIUM] CVE-2008-7279: otrs2 - The CustomerInterface component in Open Ticket Request System (OTRS) before 2.2.... The CustomerInterface component in Open Ticket Request System (OTRS) before 2.2.8 allows remote authenticated users to bypass intended access restrictions and access tickets of arbitrary customers via unspecified vectors. Scope: local bullseye: resolved (fixed in 2.3.2-1)
debian
CVE-2008-7275MEDIUMCVSS 4.3fixed in otrs2 2.3.3-1 (bullseye)2008
CVE-2008-7275 [MEDIUM] CVE-2008-7275: otrs2 - Multiple cross-site scripting (XSS) vulnerabilities in Open Ticket Request Syste... Multiple cross-site scripting (XSS) vulnerabilities in Open Ticket Request System (OTRS) before 2.3.3 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) AgentTicketMailbox or (2) CustomerTicketOverView. Scope: local bullseye: resolved (fixed in 2.3.3-1)
debian
CVE-2008-7278LOWCVSS 5.0fixed in otrs2 2.3.2-1 (bullseye)2008
CVE-2008-7278 [MEDIUM] CVE-2008-7278: otrs2 - The S/MIME feature in Open Ticket Request System (OTRS) before 2.2.5, and 2.3.x ... The S/MIME feature in Open Ticket Request System (OTRS) before 2.2.5, and 2.3.x before 2.3.0-beta1, does not properly configure the RANDFILE environment variable for OpenSSL, which might make it easier for remote attackers to decrypt e-mail messages that had lower than intended entropy available for cryptographic operations, related to inability to write to the seedin
debian
CVE-2008-7220LOWCVSS 7.5fixed in asterisk 1:1.6.2.0~rc3-1 (bullseye)2008
CVE-2008-7220 [HIGH] CVE-2008-7220: asterisk - Unspecified vulnerability in Prototype JavaScript framework (prototypejs) before... Unspecified vulnerability in Prototype JavaScript framework (prototypejs) before 1.6.0.2 allows attackers to make "cross-site ajax requests" via unknown vectors. Scope: local bullseye: resolved (fixed in 1:1.6.2.0~rc3-1) sid: resolved (fixed in 1:1.6.2.0~rc3-1)
debian
CVE-2008-7276LOWCVSS 4.6fixed in otrs2 2.3.2-1 (bullseye)2008
CVE-2008-7276 [MEDIUM] CVE-2008-7276: otrs2 - Kernel/System/Web/Request.pm in Open Ticket Request System (OTRS) before 2.3.2 c... Kernel/System/Web/Request.pm in Open Ticket Request System (OTRS) before 2.3.2 creates a directory under /tmp/ with 1274 permissions, which might allow local users to bypass intended access restrictions via standard filesystem operations, related to incorrect interpretation of 0700 as a decimal value. Scope: local bullseye: resolved (fixed in 2.3.2-1)
debian
CVE-2008-7277LOWCVSS 6.5fixed in otrs2 2.3.2-1 (bullseye)2008
CVE-2008-7277 [MEDIUM] CVE-2008-7277: otrs2 - Open Ticket Request System (OTRS) before 2.3.0-beta4 checks for the rw permissio... Open Ticket Request System (OTRS) before 2.3.0-beta4 checks for the rw permission, instead of the configured merge permission, during authorization of merge operations, which might allow remote authenticated users to bypass intended access restrictions by merging two tickets. Scope: local bullseye: resolved (fixed in 2.3.2-1)
debian
CVE-2007-2524MEDIUMCVSS 4.3PoCfixed in otrs2 2.1.1-1 (bullseye)2007
CVE-2007-2524 [MEDIUM] CVE-2007-2524: otrs2 - Cross-site scripting (XSS) vulnerability in index.pl in Open Ticket Request Syst... Cross-site scripting (XSS) vulnerability in index.pl in Open Ticket Request System (OTRS) 2.0.x allows remote attackers to inject arbitrary web script or HTML via the Subaction parameter in an AgentTicketMailbox Action. NOTE: DEBIAN:DSA-1299 originally used this identifier for an ipsec-tools issue, but the proper identifier for the ipsec-tools issue is CVE-2007-1841.
debian
CVE-2007-2383LOWCVSS 5.0fixed in asterisk 1:1.6.2.0~rc3-1 (bullseye)2007
CVE-2007-2383 [MEDIUM] CVE-2007-2383: asterisk - The Prototype (prototypejs) framework before 1.5.1 RC3 exchanges data using Java... The Prototype (prototypejs) framework before 1.5.1 RC3 exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka "JavaScript Hijack
debian