Input validation error in OTRS - CVE-2018-16587

 

Input validation error in OTRS - CVE-2018-16587

Published: September 28, 2018 / Updated: July 17, 2020


Vulnerability identifier: #VU31199
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-16587
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to manipulate data.

In Open Ticket Request System (OTRS) 4.0.x before 4.0.32, 5.0.x before 5.0.30, and 6.0.x before 6.0.11, an attacker could send a malicious email to an OTRS system. If a user with admin permissions opens it, it causes deletions of arbitrary files that the OTRS web server user has write access to.


Affected software

OTRS
otrs (Alpine package)
Opensuse
SUSE Linux

How to mitigate CVE-2018-16587

Install update from vendor's website.

OTRS - update to 6.0.11
otrs (Alpine package) - update to 6.0.33-r0

External References

Related Security Bulletins