Known vulnerabilities in OTRS - page 2

Vendor: otrs.org
Software: OTRS
Software CPE: cpe:2.3:a:otrs_org:open_ticket_request_system:*:*:*:*:*:*:*:*
Website:
Total vulnerabilities: 75
Public exploits: 3
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting OTRS OTRS is affected by 75 known vulnerabilities: 14 high, 19 medium, 42 low Critical High Medium Low

Vulnerabilities (75)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU51862 - Improper Control of Generation of Code ('Code Injection')
CVE-2019-9752
CWE-94 High
No
No
- 13.03.2019 SB2019031322
SB2021040152
#VU16057 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2018-19142
CWE-79 Low
No
No
6.0.13 26.11.2018 SB2018112610
#VU15368 - Improper Access Control
CVE-2018-14593
CWE-284 Low
No
No
4.0.31, 5.0.29, 6.0.10 15.10.2018 SB2018080406
SB2018100405
SB2021040133
#VU31198 - Improper input validation
CVE-2018-16586
CWE-20 Low
No
No
6.0.11 28.09.2018 SB2018092810
SB2018100405
SB2021040134
#VU31199 - Improper input validation
CVE-2018-16587
CWE-20 Medium
No
No
6.0.11 28.09.2018 SB2018092810
SB2018100405
SB2021040135
#VU31288 - Exposure of sensitive information to an unauthorized actor
CVE-2018-10198
CWE-200 Low
No
No
6.0.7 06.06.2018 SB2018060611
#VU10190 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2018-5117
CWE-451 Low
No
No
- 24.01.2018 SB2018012404
SB2018012409
SB2018012501
and 13 more
#VU10183 - Use After Free
CVE-2018-5096
CWE-416 High
No
No
- 24.01.2018 SB2018012501
SB2018012504
SB2018012505
and 10 more
#VU10178 - Integer overflow
CVE-2018-5095
CWE-190 High
No
No
- 24.01.2018 SB2018012404
SB2018012409
SB2018012501
and 13 more
#VU10177 - Use After Free
CVE-2018-5097
CWE-416 High
No
No
- 24.01.2018 SB2018012404
SB2018012409
SB2018012501
and 13 more
#VU10176 - Use After Free
CVE-2018-5098
CWE-416 High
No
No
- 24.01.2018 SB2018012404
SB2018012409
SB2018012501
and 13 more
#VU10175 - Use After Free
CVE-2018-5099
CWE-416 High
No
No
- 24.01.2018 SB2018012404
SB2018012409
SB2018012501
and 13 more
#VU10172 - Use After Free
CVE-2018-5102
CWE-416 High
No
No
- 24.01.2018 SB2018012404
SB2018012409
SB2018012501
and 13 more
#VU10171 - Use After Free
CVE-2018-5103
CWE-416 High
No
No
- 24.01.2018 SB2018012404
SB2018012409
SB2018012501
and 13 more
#VU10170 - Use After Free
CVE-2018-5104
CWE-416 High
No
No
- 24.01.2018 SB2018012404
SB2018012409
SB2018012501
and 13 more
#VU10167 - Memory corruption
CVE-2018-5089
CWE-119 High
No
No
- 24.01.2018 SB2018012404
SB2018012409
SB2018012501
and 13 more
#VU37774 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2017-16921
CWE-78 High
Available
No
- 08.12.2017 SB2017120819
SB2021040131
#VU9423 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2017-16664
CWE-78 High
No
No
- 27.11.2017 SB2017112126
SB2017112304
SB2021040129
#VU9422 - Exposure of sensitive information to an unauthorized actor
CVE-2017-15864
CWE-200 Low
No
No
- 24.11.2017 SB2017111429
SB2017112304
#VU32069 - Improper input validation
CVE-2017-14635
CWE-20 High
No
No
3.3.18, 4.0.25, 5.0.23 21.09.2017 SB2017092129
SB2017092135


Showing elements 21 - 40 out of 75