Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2012-4733
HistoryAug 23, 2013 - 4:55 p.m.

CVE-2012-4733

2013-08-2316:55:06
Debian Security Bug Tracker
security-tracker.debian.org
15
request tracker
rt 4.x
vulnerability
deleteticket
custom lifecycle transition
remote authenticated users
modifyticket
delete tickets
unspecified vectors
unix

CVSS2

6

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

EPSS

0.003

Percentile

71.4%

Request Tracker (RT) 4.x before 4.0.13 does not properly enforce the DeleteTicket and “custom lifecycle transition” permission, which allows remote authenticated users with the ModifyTicket permission to delete tickets via unspecified vectors.

CVSS2

6

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

EPSS

0.003

Percentile

71.4%