Summary
This host is installed with OTRS (Open Ticket Request System) and is prone to security bypass vulnerability.
Impact
Successful exploitation will allow remote attackers to read and modify objects via the OTRS SOAP interface .
Impact Level: Application
Solution
Upgrade to OTRS (Open Ticket Request System) version 2.1.8 or 2.2.6 or later, For updates refer to http://www.otrs.com/en/
Insight
An error exists in SOAP interface which fails to properly validate user credentials before performing certain actions
Affected
OTRS (Open Ticket Request System) version 2.1.0 before 2.1.8 and 2.2.0 before 2.2.6
Detection
Send a Crafted HTTP POST request and check whether it is able to get OTRS users.
References
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2008-1515 -
CVSS Base Score: 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:N
Related Vulnerabilities