CVE-2011-4459: Low severity best practical solutions request tracker vulnerability
Best Practical Solutions RT 3.x before 3.8.12 and 4.x before 4.0.6 does not properly disable groups, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by leveraging a group membership.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4459?
The severity of CVE-2011-4459 is classified as moderate, as it allows authenticated users to bypass intended access restrictions.
How do I fix CVE-2011-4459?
To fix CVE-2011-4459, upgrade your Best Practical Solutions RT installation to version 3.8.12 or 4.0.6 or later.
What versions are affected by CVE-2011-4459?
CVE-2011-4459 affects Best Practical Solutions RT versions 3.8.7 through 3.8.11 and 4.0.0 through 4.0.5.
What impact does CVE-2011-4459 have on users?
CVE-2011-4459 allows remote authenticated users to exploit group memberships, leading to unauthorized access to restricted functionalities.
Is CVE-2011-4459 a remote or local vulnerability?
CVE-2011-4459 is considered a remote vulnerability as it can be exploited by authenticated users accessing the server from a remote location.