Cryptographic issues in OTRS - CVE-2011-1433

 

Cryptographic issues in OTRS - CVE-2011-1433

Published: March 18, 2011 / Updated: August 11, 2020


Vulnerability identifier: #VU45219
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2011-1433
CWE-ID: CWE-310
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: otrs.org
Affected software:
OTRS

Detailed vulnerability description

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

The (1) AgentInterface and (2) CustomerInterface components in Open Ticket Request System (OTRS) before 3.0.6 place cleartext credentials into the session data in the database, which makes it easier for context-dependent attackers to obtain sensitive information by reading the _UserLogin and _UserPW fields.


How to mitigate CVE-2011-1433

Install update from vendor's website.

Sources