First published: Tue Feb 09 2010(Updated: )
Multiple SQL injection vulnerabilities in Kernel/System/Ticket.pm in OTRS-Core in Open Ticket Request System (OTRS) 2.1.x before 2.1.9, 2.2.x before 2.2.9, 2.3.x before 2.3.5, and 2.4.x before 2.4.7 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OTRS | =2.4.1 | |
OTRS | =2.1.3 | |
OTRS | =2.2.4 | |
OTRS | =2.2.5 | |
OTRS | =2.4.5 | |
OTRS | =2.1.8 | |
OTRS | =2.1.5 | |
OTRS | =2.3.4 | |
OTRS | =2.1.2 | |
OTRS | =2.4.6 | |
OTRS | =2.2.6 | |
OTRS | =2.3.3 | |
OTRS | =2.2.2 | |
OTRS | =2.4.3 | |
OTRS | =2.3.1 | |
OTRS | =2.1.6 | |
OTRS | =2.4.4 | |
OTRS | =2.1.7 | |
OTRS | =2.4.2 | |
OTRS | =2.2.7 | |
OTRS | =2.2.1 | |
OTRS | =2.1.4 | |
OTRS | =2.3.2 | |
OTRS | =2.1.1 | |
OTRS | =2.2.3 | |
OTRS | =2.2.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0438 is classified as a medium severity vulnerability due to its potential for remote authenticated users to execute arbitrary SQL commands.
To fix CVE-2010-0438, you should upgrade to the latest versions of OTRS that are not affected by this vulnerability, specifically versions 2.1.9, 2.2.9, 2.3.5, or 2.4.7 and later.
CVE-2010-0438 affects multiple versions of OTRS prior to the specified patched releases, allowing remote authenticated users to exploit SQL injection vulnerabilities.
CVE-2010-0438 specifically describes multiple SQL injection vulnerabilities that can be exploited by remote authenticated users via unspecified vectors.
Key vulnerable versions of OTRS include 2.1.3, 2.2.4, 2.3.4, and 2.4.6, prior to their respective fixed releases.