CVE-2011-1433: Medium severity otrs vulnerability
The (1) AgentInterface and (2) CustomerInterface components in Open Ticket Request System (OTRS) before 3.0.6 place cleartext credentials into the session data in the database, which makes it easier for context-dependent attackers to obtain sensitive information by reading the UserLogin and UserPW fields.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1433?
CVE-2011-1433 is considered a high-severity vulnerability due to the exposure of cleartext credentials in session data.
How do I fix CVE-2011-1433?
To fix CVE-2011-1433, upgrade to OTRS version 3.0.6 or later, where this issue has been addressed.
What type of attacks can exploit CVE-2011-1433?
CVE-2011-1433 can be exploited by context-dependent attackers who can access the database and read sensitive information.
Which versions of OTRS are affected by CVE-2011-1433?
CVE-2011-1433 affects various OTRS versions prior to 3.0.6, including multiple beta releases.
What components are involved in CVE-2011-1433?
CVE-2011-1433 involves the AgentInterface and CustomerInterface components of the Open Ticket Request System.