CVE-2009-5055: Low severity otrs vulnerability
Open Ticket Request System (OTRS) before 2.4.4 grants ticket access on the basis of single-digit substrings of the CustomerID value, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by visiting a ticket, as demonstrated by leveraging the CustomerID 12 account to read tickets that should be available only to CustomerID 1 or CustomerID 2.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2009-5055?
CVE-2009-5055 is classified with a medium severity level as it allows bypass of access controls.
How do I fix CVE-2009-5055?
To fix CVE-2009-5055, upgrade to OTRS version 2.4.4 or later.
What types of systems are affected by CVE-2009-5055?
CVE-2009-5055 affects all versions of OTRS prior to 2.4.4, including specific beta and release candidates.
What impact does CVE-2009-5055 have on OTRS?
CVE-2009-5055 allows remote authenticated users to access tickets they should not have permission to view.
Is there a workaround for CVE-2009-5055?
There is no effective workaround for CVE-2009-5055 other than upgrading the software.