SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-36097

Agents are able to lock the ticket without the "Owner" permission.

MEDIUM 4.3EPSS 0.52%

Does this matter?

Lower severity and a low EPSS score (0.52%). Track it; it rarely justifies an emergency change on its own.

Description

Agents are able to lock the ticket without the "Owner" permission. Once the ticket is locked, it could be moved to the queue where the agent has "rw" permissions and gain a full control. This issue affects: OTRS AG OTRS 8.0.x version: 8.0.16 and prior versions.

CVSS 3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
EPSS
0.52% probability · 43th percentile
CISA KEV
Not listed
Weakness
CWE-266
Affected
otrs/otrs
Source
security@otrs.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.