Input validation error in OTRS - CVE-2011-2746

 

Input validation error in OTRS - CVE-2011-2746

Published: August 29, 2011 / Updated: August 11, 2020


Vulnerability identifier: #VU44770
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2011-2746
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote #AU# to gain access to sensitive information.

Unspecified vulnerability in Kernel/Modules/AdminPackageManager.pm in OTRS-Core in Open Ticket Request System (OTRS) 2.x before 2.4.11 and 3.x before 3.0.10 allows remote authenticated administrators to read arbitrary files via unknown vectors.


Affected software

OTRS

How to mitigate CVE-2011-2746

Install update from vendor's website.


External References

Related Security Bulletins