CVE-2022-35489: Medium severity Zammad Zammad vulnerability
In Zammad 5.2.0, customers who have secondary organizations assigned were able to see all organizations of the system rather than only those to which they are assigned.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-35489?
CVE-2022-35489 is a vulnerability in Zammad 5.2.0 that allows customers with secondary organizations assigned to see all organizations of the system instead of only those they are assigned to.
How does CVE-2022-35489 impact Zammad 5.2.0?
CVE-2022-35489 allows customers with secondary organizations assigned to view all organizations in the system, which can lead to unauthorized access and privacy breaches.
What is the severity of CVE-2022-35489?
CVE-2022-35489 has a severity level of medium, with a severity value of 6.5.
How can I fix CVE-2022-35489?
To fix CVE-2022-35489, it is recommended to upgrade to a version of Zammad that is not affected by this vulnerability.
Where can I find more information about CVE-2022-35489?
For more information about CVE-2022-35489, you can refer to the advisory on the Zammad website: https://zammad.com/de/advisories/zaa-2022-06