PT-2020-9940 · Otrs+2 · Otrs+2

Published

2020-01-01

·

Updated

2023-08-31

·

CVE-2019-18179

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Open Ticket Request System (OTRS) versions 7.0.x through 7.0.12 Open Ticket Request System (OTRS) Community Edition versions 5.0.x through 5.0.38 Open Ticket Request System (OTRS) Community Edition versions 6.0.x through 6.0.23
Description An issue was discovered in Open Ticket Request System (OTRS) where an attacker logged in as an agent can list tickets assigned to other agents, including tickets in a queue where the attacker does not have permissions.
Recommendations For versions 7.0.x through 7.0.12, update to a version outside of this range to mitigate the risk. For Community Edition versions 5.0.x through 5.0.38, update to a version outside of this range to mitigate the risk. For Community Edition versions 6.0.x through 6.0.23, update to a version outside of this range to mitigate the risk. As a temporary workaround, consider restricting access to sensitive queues to minimize the risk of exploitation.

Fix

Related Identifiers

ALT-PU-2020-2649
ALT-PU-2020-2748
CVE-2019-18179
DLA-2053-1
DLA-3551-1
OPENSUSE-SU-2020:0551-1
OPENSUSE-SU-2020:1475-1
OPENSUSE-SU-2020:1509-1
OPENSUSE-SU-2020_0551-1
OPENSUSE-SU-2020_1475-1

Affected Products

Alt Linux
Otrs
Suse