PT-2021-21111 · Otrs Ag+1 · Otrs+2

Published

2021-07-26

·

Updated

2024-08-06

·

CVE-2021-36091

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: OTRS AG (OTRS) Community Edition versions 6.0.1 and later OTRS AG OTRS versions prior to 7.0.27
Description: The issue allows agents to list appointments in calendars without the necessary permissions.
Recommendations: For OTRS AG (OTRS) Community Edition versions 6.0.1 and later, update to a version that includes the fix for this issue. For OTRS AG OTRS versions prior to 7.0.27, update to version 7.0.27 or later to resolve the issue.

Fix

Incorrect Authorization

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-2917
ALT-PU-2021-3039
ALT-PU-2021-3058
ALT-PU-2024-10583
CVE-2021-36091
DLA-3551-1

Affected Products

Alt Linux
Otrs
Otrs Community Edition