PT-2019-12826 · Otrs+2 · Otrs+2

Jens Meister

·

Publicado

2019-06-11

·

Atualizado

2023-08-31

·

CVE-2019-12497

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Open Ticket Request System (OTRS) versions 7.0.x through 7.0.8 Open Ticket Request System (OTRS) Community Edition versions 6.0.x through 6.0.19 Open Ticket Request System (OTRS) Community Edition versions 5.0.x through 5.0.36
Description An issue was discovered in the customer or external frontend of Open Ticket Request System (OTRS), where personal information of agents, such as name and mail address, can be disclosed in external notes.
Recommendations For versions 7.0.x through 7.0.8, consider restricting access to external notes to minimize the risk of exploitation. For Community Edition versions 6.0.x through 6.0.19, avoid displaying personal information of agents in external notes until a fix is available. For Community Edition versions 5.0.x through 5.0.36, temporarily disable the feature of displaying agent information in external notes as a mitigation measure.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-3068
ALT-PU-2019-3183
CVE-2019-12497
DLA-1816-1
DLA-3551-1
OPENSUSE-SU-2020:0551-1
OPENSUSE-SU-2020:1475-1
OPENSUSE-SU-2020:1509-1
OPENSUSE-SU-2020_0551-1
OPENSUSE-SU-2020_1475-1

Produtos afetados

Alt Linux
Otrs
Suse