PT-2019-12826 · Otrs+2 · Otrs+2
Jens Meister
·
Published
2019-06-11
·
Updated
2023-08-31
·
CVE-2019-12497
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Open Ticket Request System (OTRS) versions 7.0.x through 7.0.8
Open Ticket Request System (OTRS) Community Edition versions 6.0.x through 6.0.19
Open Ticket Request System (OTRS) Community Edition versions 5.0.x through 5.0.36
Description
An issue was discovered in the customer or external frontend of Open Ticket Request System (OTRS), where personal information of agents, such as name and mail address, can be disclosed in external notes.
Recommendations
For versions 7.0.x through 7.0.8, consider restricting access to external notes to minimize the risk of exploitation.
For Community Edition versions 6.0.x through 6.0.19, avoid displaying personal information of agents in external notes until a fix is available.
For Community Edition versions 5.0.x through 5.0.36, temporarily disable the feature of displaying agent information in external notes as a mitigation measure.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Otrs
Suse