The SOAP interface in OTRS 2.1.x before 2.1.8 and 2.2.x before 2.2.6 allows remote attackers to "read and modify objects" via SOAP requests, related to "Missing security checks."
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 69.6%