VulnerabilityModified
CVE-2008-1515
The SOAP interface in OTRS 2.1.x before 2.1.8 and 2.2.x before 2.2.6 allows remote attackers to "read and modify objects" via SOAP requests, related to "Missing security checks."
MEDIUM 6.4EPSS 2.02%
Does this matter?
Lower severity and a low EPSS score (2.02%). Track it; it rarely justifies an emergency change on its own.
Description
The SOAP interface in OTRS 2.1.x before 2.1.8 and 2.2.x before 2.2.6 allows remote attackers to "read and modify objects" via SOAP requests, related to "Missing security checks."
- CVSS 2.0
- 6.4 MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
- EPSS
- 2.02% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- otrs/otrs
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00005.htmlThird Party Advisory
- http://otrs.org/advisory/OSA-2008-01-en/Vendor Advisory
- http://secunia.com/advisories/29585Third Party Advisory
- http://secunia.com/advisories/29622Third Party Advisory
- http://secunia.com/advisories/29859Third Party Advisory
- http://www.securityfocus.com/bid/28647Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41577Third Party Advisory, VDB Entry
- https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00284.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00005.htmlThird Party Advisory
- http://otrs.org/advisory/OSA-2008-01-en/Vendor Advisory
- http://secunia.com/advisories/29585Third Party Advisory
- http://secunia.com/advisories/29622Third Party Advisory
- http://secunia.com/advisories/29859Third Party Advisory
- http://www.securityfocus.com/bid/28647Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41577Third Party Advisory, VDB Entry
- https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00284.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.