PT-2019-12916 · Otrs+2 · Otrs Community Edition+2

Published

2019-08-12

·

Updated

2023-08-31

·

CVE-2019-12746

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Open Ticket Request System (OTRS) Community Edition versions 5.0.x through 5.0.36 Open Ticket Request System (OTRS) Community Edition versions 6.0.x through 6.0.19
Description An issue was discovered where a user logged into OTRS as an agent might unknowingly disclose their session ID by sharing the link of an embedded ticket article with third parties. This identifier can be potentially abused in order to impersonate the agent user.
Recommendations For versions 5.0.x through 5.0.36, consider restricting access to embedded ticket articles to prevent unintended session ID disclosure. For versions 6.0.x through 6.0.19, consider implementing measures to protect session IDs from being shared or abused, such as using secure communication protocols or encrypting session identifiers.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

ALT-PU-2019-3068
ALT-PU-2019-3183
CVE-2019-12746
DLA-1877-1
DLA-3551-1
OPENSUSE-SU-2020:0551-1
OPENSUSE-SU-2020:1475-1
OPENSUSE-SU-2020:1509-1
OPENSUSE-SU-2020_0551-1
OPENSUSE-SU-2020_1475-1

Affected Products

Alt Linux
Otrs Community Edition
Suse