CVE-2010-4768
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Open Ticket Request System (OTRS) before 2.3.5 does not properly disable hidden permissions, which allows remote authenticated users to bypass intended queue access restrictions in opportunistic circumstances by visiting a ticket, related to a certain ordering of permission-set and permission-remove operations involving both hidden permissions and other permissions.
Open Ticket Request System (OTRS) anteriores a v2.3.5 no desactiva de forma adecuada los permisos ocultos, lo que permite a usuarios remotos autenticados eludir las restricciones de acceso a la cola previstos, en ciertas circunstancias al visitar un ticket, está relacionado con un cierto orden del conjunto de permisos y eliminación de los mismos, que implica a ambos, permisos ocultos y otros.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2011-03-18 CVE Reserved
- 2011-03-18 CVE Published
- 2024-09-16 CVE Updated
- 2024-09-16 First Exploit
- 2024-09-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://source.otrs.org/viewvc.cgi/otrs/CHANGES?revision=1.1807 | X_refsource_confirm |
URL | Date | SRC |
---|---|---|
http://bugs.otrs.org/show_bug.cgi?id=3499 | 2024-09-16 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | <= 2.3.4 Search vendor "Otrs" for product "Otrs" and version " <= 2.3.4" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 0.5 Search vendor "Otrs" for product "Otrs" and version "0.5" | beta1 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 0.5 Search vendor "Otrs" for product "Otrs" and version "0.5" | beta2 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 0.5 Search vendor "Otrs" for product "Otrs" and version "0.5" | beta3 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 0.5 Search vendor "Otrs" for product "Otrs" and version "0.5" | beta4 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 0.5 Search vendor "Otrs" for product "Otrs" and version "0.5" | beta5 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 0.5 Search vendor "Otrs" for product "Otrs" and version "0.5" | beta6 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 0.5 Search vendor "Otrs" for product "Otrs" and version "0.5" | beta7 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 0.5 Search vendor "Otrs" for product "Otrs" and version "0.5" | beta8 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.0 Search vendor "Otrs" for product "Otrs" and version "1.0" | rc1 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.0 Search vendor "Otrs" for product "Otrs" and version "1.0" | rc2 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.0 Search vendor "Otrs" for product "Otrs" and version "1.0" | rc3 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.0.0 Search vendor "Otrs" for product "Otrs" and version "1.0.0" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.0.1 Search vendor "Otrs" for product "Otrs" and version "1.0.1" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.0.2 Search vendor "Otrs" for product "Otrs" and version "1.0.2" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.1 Search vendor "Otrs" for product "Otrs" and version "1.1" | rc1 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.1.0 Search vendor "Otrs" for product "Otrs" and version "1.1.0" | rc1 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.1.0 Search vendor "Otrs" for product "Otrs" and version "1.1.0" | rc2 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.1.1 Search vendor "Otrs" for product "Otrs" and version "1.1.1" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.1.2 Search vendor "Otrs" for product "Otrs" and version "1.1.2" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.1.3 Search vendor "Otrs" for product "Otrs" and version "1.1.3" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.1.4 Search vendor "Otrs" for product "Otrs" and version "1.1.4" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.2.0 Search vendor "Otrs" for product "Otrs" and version "1.2.0" | beta1 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.2.0 Search vendor "Otrs" for product "Otrs" and version "1.2.0" | beta2 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.2.0 Search vendor "Otrs" for product "Otrs" and version "1.2.0" | beta3 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.2.1 Search vendor "Otrs" for product "Otrs" and version "1.2.1" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.2.2 Search vendor "Otrs" for product "Otrs" and version "1.2.2" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.2.3 Search vendor "Otrs" for product "Otrs" and version "1.2.3" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.2.4 Search vendor "Otrs" for product "Otrs" and version "1.2.4" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.3.0 Search vendor "Otrs" for product "Otrs" and version "1.3.0" | beta1 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.3.0 Search vendor "Otrs" for product "Otrs" and version "1.3.0" | beta2 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.3.0 Search vendor "Otrs" for product "Otrs" and version "1.3.0" | beta3 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.3.0 Search vendor "Otrs" for product "Otrs" and version "1.3.0" | beta4 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.3.1 Search vendor "Otrs" for product "Otrs" and version "1.3.1" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.3.2 Search vendor "Otrs" for product "Otrs" and version "1.3.2" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.3.3 Search vendor "Otrs" for product "Otrs" and version "1.3.3" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.0.0 Search vendor "Otrs" for product "Otrs" and version "2.0.0" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.0.0 Search vendor "Otrs" for product "Otrs" and version "2.0.0" | beta1 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.0.0 Search vendor "Otrs" for product "Otrs" and version "2.0.0" | beta2 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.0.0 Search vendor "Otrs" for product "Otrs" and version "2.0.0" | beta4 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.0.0 Search vendor "Otrs" for product "Otrs" and version "2.0.0" | beta5 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.0.0 Search vendor "Otrs" for product "Otrs" and version "2.0.0" | beta6 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.0.1 Search vendor "Otrs" for product "Otrs" and version "2.0.1" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.0.2 Search vendor "Otrs" for product "Otrs" and version "2.0.2" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.0.3 Search vendor "Otrs" for product "Otrs" and version "2.0.3" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.0.4 Search vendor "Otrs" for product "Otrs" and version "2.0.4" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.0.5 Search vendor "Otrs" for product "Otrs" and version "2.0.5" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.1.0 Search vendor "Otrs" for product "Otrs" and version "2.1.0" | beta1 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.1.0 Search vendor "Otrs" for product "Otrs" and version "2.1.0" | beta2 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.1.1 Search vendor "Otrs" for product "Otrs" and version "2.1.1" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.1.2 Search vendor "Otrs" for product "Otrs" and version "2.1.2" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.1.3 Search vendor "Otrs" for product "Otrs" and version "2.1.3" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.1.4 Search vendor "Otrs" for product "Otrs" and version "2.1.4" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.1.5 Search vendor "Otrs" for product "Otrs" and version "2.1.5" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.1.6 Search vendor "Otrs" for product "Otrs" and version "2.1.6" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.1.7 Search vendor "Otrs" for product "Otrs" and version "2.1.7" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.1.8 Search vendor "Otrs" for product "Otrs" and version "2.1.8" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.1.9 Search vendor "Otrs" for product "Otrs" and version "2.1.9" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.2.0 Search vendor "Otrs" for product "Otrs" and version "2.2.0" | beta1 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.2.0 Search vendor "Otrs" for product "Otrs" and version "2.2.0" | beta2 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.2.0 Search vendor "Otrs" for product "Otrs" and version "2.2.0" | beta3 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.2.0 Search vendor "Otrs" for product "Otrs" and version "2.2.0" | beta4 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.2.0 Search vendor "Otrs" for product "Otrs" and version "2.2.0" | rc1 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.2.1 Search vendor "Otrs" for product "Otrs" and version "2.2.1" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.2.2 Search vendor "Otrs" for product "Otrs" and version "2.2.2" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.2.3 Search vendor "Otrs" for product "Otrs" and version "2.2.3" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.2.4 Search vendor "Otrs" for product "Otrs" and version "2.2.4" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.2.5 Search vendor "Otrs" for product "Otrs" and version "2.2.5" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.2.6 Search vendor "Otrs" for product "Otrs" and version "2.2.6" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.2.7 Search vendor "Otrs" for product "Otrs" and version "2.2.7" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.2.8 Search vendor "Otrs" for product "Otrs" and version "2.2.8" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.2.9 Search vendor "Otrs" for product "Otrs" and version "2.2.9" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.3.0 Search vendor "Otrs" for product "Otrs" and version "2.3.0" | beta1 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.3.0 Search vendor "Otrs" for product "Otrs" and version "2.3.0" | beta2 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.3.0 Search vendor "Otrs" for product "Otrs" and version "2.3.0" | beta3 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.3.0 Search vendor "Otrs" for product "Otrs" and version "2.3.0" | beta4 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.3.0 Search vendor "Otrs" for product "Otrs" and version "2.3.0" | rc1 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.3.1 Search vendor "Otrs" for product "Otrs" and version "2.3.1" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.3.2 Search vendor "Otrs" for product "Otrs" and version "2.3.2" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.3.3 Search vendor "Otrs" for product "Otrs" and version "2.3.3" | - |
Affected
|