VulnerabilityModified
CVE-2019-18179
An attacker who is logged into OTRS as an agent is able to list tickets assigned to other agents, even tickets in a queue where the attacker doesn't have permissions.
MEDIUM 4.3EPSS 1.57%
Does this matter?
Lower severity and a low EPSS score (1.57%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.12, and Community Edition 5.0.x through 5.0.38 and 6.0.x through 6.0.23. An attacker who is logged into OTRS as an agent is able to list tickets assigned to other agents, even tickets in a queue where the attacker doesn't have permissions.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.57% probability · 74th percentile
- CISA KEV
- Not listed
- Affected
- otrs/otrs · debian/debian linux · opensuse/backports sle · opensuse/leap
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00038.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00066.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00077.htmlMailing List, Third Party Advisory
- https://community.otrs.com/security-advisory-2019-14-security-update-for-otrs-framework/Patch, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2020/01/msg00000.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00038.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00066.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00077.htmlMailing List, Third Party Advisory
- https://community.otrs.com/security-advisory-2019-14-security-update-for-otrs-framework/Patch, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2020/01/msg00000.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.