Vulnerability Bulletins

DSA-3124 otrs2 - security update

   
Affected software Debian
 
Thorsten Eckel of Znuny GMBH and Remo Staeuble of InfoGuard discovereda privilege escalation vulnerability in otrs2, the Open Ticket RequestSystem. An attacker with valid OTRS credentials could access andmanipulate ticket data of other users via the GenericInterface, if aticket webservice is configured and not additionally secured.

More info:

https://www.debian.org/security/2015/dsa-3124