MEDIUM
An issue was discovered in Open Ticket Request System (OTRS) 5.x through 5.0.34, 6.x through 6.0.17, and 7.x through 7.0.6
Published May 21, 2019
6.5
MEDIUMCVSS 3.1
EPSS 1.08%
Description
An issue was discovered in Open Ticket Request System (OTRS) 5.x through 5.0.34, 6.x through 6.0.17, and 7.x through 7.0.6. An attacker who is logged into OTRS as an agent user with appropriate permissions may try to import carefully crafted Report Statistics XML that will result in reading of arbitrary files on the OTRS filesystem.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00038.html vendor-advisoryx_refsource_SUSEBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00066.html vendor-advisoryx_refsource_SUSEBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00077.html vendor-advisoryx_refsource_SUSEBroken Link
- https://community.otrs.com/security-advisory-2019-04-security-update-for-otrs-framework/ x_refsource_CONFIRMVendor Advisory
- https://lists.debian.org/debian-lts-announce/2019/05/msg00003.html x_refsource_MISCMailing ListThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00038.html | vendor-advisoryx_refsource_SUSEBroken Link | |
| http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00066.html | vendor-advisoryx_refsource_SUSEBroken Link | |
| http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00077.html | vendor-advisoryx_refsource_SUSEBroken Link | |
| https://community.otrs.com/security-advisory-2019-04-security-update-for-otrs-framework/ | x_refsource_CONFIRMVendor Advisory | |
| https://lists.debian.org/debian-lts-announce/2019/05/msg00003.html | x_refsource_MISCMailing ListThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 21, 2019
Updated Aug 4, 2024
Reserved Mar 20, 2019
Link CVE-2019-9892
CISA Vulnrichment
Updated n/a