Information disclosure in OTRS - CVE-2017-15864

 

Information disclosure in OTRS - CVE-2017-15864

Published: November 24, 2017 / Updated: November 27, 2017


Vulnerability identifier: #VU9422
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-15864
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated attacker to obtain potentially sensitive information.

The vulnerability exists due to insufficient input validation. A remote attacker who is logged into OTRS as an agent can request special URLs from OTRS, and retrieve any configuration information, including database credentials.


Affected software

OTRS

How to mitigate CVE-2017-15864

Update to version 3.3.19.


External References

Related Security Bulletins