CVE detail
CVE-2009-5055 — CVE-2009-5055
Published 2011-03-18 · Modified 2026-06-16 · Vendor otrs · Product otrs · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0090
EPSS probability
exploitation probability, 30d
56.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Open Ticket Request System (OTRS) before 2.4.4 grants ticket access on the basis of single-digit substrings of the CustomerID value, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by visiting a ticket, as demonstrated by leveraging the CustomerID 12 account to read tickets that should be available only to CustomerID 1 or CustomerID 2.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References