CVE-2009-5056: Input Validation
Open Ticket Request System (OTRS) before 2.4.0-beta2 does not properly enforce the moveinto permission setting for a queue, which allows remote authenticated users to bypass intended access restrictions and read a ticket by watching this ticket, and then selecting the ticket from the watched-tickets list.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-5056?
CVE-2009-5056 has a medium severity rating because it allows remote authenticated users to circumvent access restrictions.
How do I fix CVE-2009-5056?
To fix CVE-2009-5056, upgrade OTRS to version 2.4.0-beta2 or later.
What is affected by CVE-2009-5056?
CVE-2009-5056 affects OTRS versions prior to 2.4.0-beta2, including multiple beta and release candidates.
What can attackers do with CVE-2009-5056?
Attackers can bypass intended access restrictions and read tickets they should not have access to by using the watched-ticket feature.
When was CVE-2009-5056 disclosed?
CVE-2009-5056 was disclosed in 2009 as part of an ongoing security review of the OTRS application.