PT-2017-18844 · Otrs+1 · Otrs+1

Joerg-Thomas Vogt

·

Published

2017-06-09

·

Updated

2019-10-03

·

CVE-2017-9324

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Open Ticket Request System (OTRS) versions 3.3.x through 3.3.16 Open Ticket Request System (OTRS) versions 4.x through 4.0.23 Open Ticket Request System (OTRS) versions 5.x through 5.0.19
Description An issue allows an attacker with agent permission to gain administrative privileges by opening a specific URL in a browser. This enables the attacker to read and change all system settings. The vulnerable URLs contain "index.pl?Action=Installer" with ";Subaction=Intro", ";Subaction=Start", or ";Subaction=System" appended.
Recommendations For versions 3.3.x through 3.3.16, avoid using the "index.pl?Action=Installer" URL with ";Subaction=Intro", ";Subaction=Start", or ";Subaction=System" until a patch is available. For versions 4.x through 4.0.23, restrict access to the "index.pl?Action=Installer" URL with ";Subaction=Intro", ";Subaction=Start", or ";Subaction=System" to minimize the risk of exploitation. For versions 5.x through 5.0.19, consider disabling the Action=Installer functionality until a fix is provided.

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-2623
CVE-2017-9324
DSA-3876-1

Affected Products

Alt Linux
Otrs