XML injection in Debian Linux - CVE-2019-9892

 

XML injection in Debian Linux - CVE-2019-9892

Published: May 22, 2019 / Updated: August 8, 2020


Vulnerability identifier: #VU35890
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-9892
CWE-ID: CWE-91
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated user to gain access to sensitive information.

An issue was discovered in Open Ticket Request System (OTRS) 5.x through 5.0.34, 6.x through 6.0.17, and 7.x through 7.0.6. An attacker who is logged into OTRS as an agent user with appropriate permissions may try to import carefully crafted Report Statistics XML that will result in reading of arbitrary files on the OTRS filesystem.


Affected software

Debian Linux
otrs (Alpine package)

How to mitigate CVE-2019-9892

Install update from vendor's website.

otrs (Alpine package) - update to 6.0.33-r0

External References

Related Security Bulletins