PT-2020-9401 · Otrs+1 · Otrs+1

Tobias Kirchner

·

Published

2020-03-10

·

Updated

2023-01-27

·

CVE-2019-13457

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Open Ticket Request System (OTRS) versions 7.0.x through 7.0.8
Description: An issue was discovered in Open Ticket Request System (OTRS) where a customer user can use the search results to disclose information from their "company" tickets, even when the CustomerDisableCompanyTicketAccess setting is turned on. This allows access to tickets with the same CustomerID.
Recommendations: For versions 7.0.x through 7.0.8, consider disabling the search function for customer users until a patch is available, or adjust the CustomerDisableCompanyTicketAccess setting to restrict access to company tickets. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2019-13457
OPENSUSE-SU-2020:0551-1
OPENSUSE-SU-2020:1475-1
OPENSUSE-SU-2020:1509-1
OPENSUSE-SU-2020_0551-1
OPENSUSE-SU-2020_1475-1

Affected Products

Otrs
Suse