SB2019031319 - Input validation error in OTRS



SB2019031319 - Input validation error in OTRS

Published: March 13, 2019 Updated: August 8, 2020

Security Bulletin ID SB2019031319
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Input validation error (CVE-ID: CVE-2018-20800)

The vulnerability allows a remote authenticated user to manipulate data.

An issue was discovered in Open Ticket Request System (OTRS) 5.0.31 and 6.0.13. Users updating to 6.0.13 (also patchlevel updates) or 5.0.31 (only major updates) will experience data loss in their agent preferences table.


Remediation

Install update from vendor's website.