Open Ticket Request System (OTRS) 4.0.24

CPE Details

Open Ticket Request System (OTRS) 4.0.24
4.0.24
2019-03-29
15h42 +00:00
2019-03-29
15h42 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:otrs:otrs:4.0.24:*:*:*:*:*:*:*

Informations

Vendor

otrs

Product

otrs

Version

4.0.24

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2021-36100 2022-03-21 09h15 +00:00 Specially crafted string in OTRS system configuration can allow the execution of any system command.
8.8
High
CVE-2020-1778 2020-11-23 15h32 +00:00 When OTRS uses multiple backends for user authentication (with LDAP), agents are able to login even if the account is set to invalid. This issue affects OTRS; 8.0.9 and prior versions.
4.3
Medium
CVE-2017-17476 2017-12-20 16h00 +00:00 Open Ticket Request System (OTRS) 4.0.x before 4.0.28, 5.0.x before 5.0.26, and 6.0.x before 6.0.3, when cookie support is disabled, might allow remote attackers to hijack web sessions and consequently gain privileges via a crafted email.
8.8
High
CVE-2017-16854 2017-12-08 16h00 +00:00 In Open Ticket Request System (OTRS) through 3.3.20, 4 through 4.0.26, 5 through 5.0.24, and 6 through 6.0.1, an attacker who is logged in as a customer can use the ticket search form to disclose internal article information of their customer tickets.
6.5
Medium
CVE-2017-16921 2017-12-08 14h00 +00:00 In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.26, an attacker who is logged into OTRS as an agent can manipulate form parameters (related to PGP) and execute arbitrary shell commands with the permissions of the OTRS or web server user.
8.8
High
CVE-2017-16664 2017-11-21 13h00 +00:00 Code injection exists in Kernel/System/Spelling.pm in Open Ticket Request System (OTRS) 5 before 5.0.24, 4 before 4.0.26, and 3.3 before 3.3.20. In the agent interface, an authenticated remote attacker can execute shell commands as the webserver user via URL manipulation.
8.8
High
CVE-2017-14635 2017-09-21 11h00 +00:00 In Open Ticket Request System (OTRS) 3.3.x before 3.3.18, 4.x before 4.0.25, and 5.x before 5.0.23, remote authenticated users can leverage statistics-write permissions to gain privileges via code injection.
8.8
High
CVE-2011-2385 2011-07-19 18h00 +00:00 The iPhoneHandle package 0.9.x before 0.9.7 and 1.0.x before 1.0.3 in Open Ticket Request System (OTRS) does not properly restrict use of the iPhoneHandle interface, which allows remote authenticated users to gain privileges, and consequently read or modify OTRS core objects, via unspecified vectors.
6.5