This issue affects:
* OTRS 7.0.X
* OTRS 8.0.X
* OTRS 2023.X
* OTRS 2024.X
* ((OTRS)) Community Edition: 6.0.x
Products based on the ((OTRS)) Community Edition also very likely to be affected
No analysis available yet.
Vendor Solution
Update to OTRS 2025.1.x. Please note that there will be no OTRS 7 patches
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-40288 | An improper privilege management vulnerability in OTRS Generic Interface module allows change of the Ticket status even if the user only has ro permissions. This issue affects: * OTRS 7.0.X * OTRS 8.0.X * OTRS 2023.X * OTRS 2024.X * ((OTRS)) Community Edition: 6.0.x Products based on the ((OTRS)) Community Edition also very likely to be affected |
Wed, 12 Feb 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 27 Jan 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper privilege management vulnerability in OTRS Generic Interface module allows change of the Ticket status even if the user only has ro permissions. This issue affects: * OTRS 7.0.X * OTRS 8.0.X * OTRS 2023.X * OTRS 2024.X * ((OTRS)) Community Edition: 6.0.x Products based on the ((OTRS)) Community Edition also very likely to be affected | |
| Title | Improper check of permissions in Generic Interface | |
| Weaknesses | CWE-269 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: OTRS
Published:
Updated: 2025-02-12T20:41:31.804Z
Reserved: 2024-08-13T13:38:47.973Z
Link: CVE-2024-43446
Updated: 2025-02-12T20:36:35.059Z
Status : Deferred
Published: 2025-01-27T06:15:24.033
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-43446
No data.
OpenCVE Enrichment
No data.
EUVD