Open Ticket Request System (OTRS) 5.0.42 Community Edition

CPE Details

Open Ticket Request System (OTRS) 5.0.42 Community Edition
5.0.42
2020-03-31
17h05 +00:00
2020-03-31
17h05 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:otrs:otrs:5.0.42:*:*:*:community:*:*:*

Informations

Vendor

otrs

Product

otrs

Version

5.0.42

Software Edition

community

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2021-36100 2022-03-21 09h15 +00:00 Specially crafted string in OTRS system configuration can allow the execution of any system command.
8.8
High
CVE-2020-1778 2020-11-23 15h32 +00:00 When OTRS uses multiple backends for user authentication (with LDAP), agents are able to login even if the account is set to invalid. This issue affects OTRS; 8.0.9 and prior versions.
4.3
Medium
CVE-2020-1776 2020-07-20 21h04 +00:00 When an agent user is renamed or set to invalid the session belonging to the user is keept active. The session can not be used to access ticket data in the case the agent is invalid. This issue affects ((OTRS)) Community Edition: 6.0.28 and prior versions. OTRS: 7.0.18 and prior versions, 8.0.4. and prior versions.
4.3
Medium
CVE-2020-1774 2020-04-28 13h54 +00:00 When user downloads PGP or S/MIME keys/certificates, exported file has same name for private and public keys. Therefore it's possible to mix them and to send private key to the third-party instead of public key. This issue affects ((OTRS)) Community Edition: 5.0.42 and prior versions, 6.0.27 and prior versions. OTRS: 7.0.16 and prior versions.
4.9
Medium
CVE-2011-2385 2011-07-19 18h00 +00:00 The iPhoneHandle package 0.9.x before 0.9.7 and 1.0.x before 1.0.3 in Open Ticket Request System (OTRS) does not properly restrict use of the iPhoneHandle interface, which allows remote authenticated users to gain privileges, and consequently read or modify OTRS core objects, via unspecified vectors.
6.5