First published: Fri Mar 18 2011(Updated: )
The (1) AgentInterface and (2) CustomerInterface components in Open Ticket Request System (OTRS) before 3.0.6 place cleartext credentials into the session data in the database, which makes it easier for context-dependent attackers to obtain sensitive information by reading the _UserLogin and _UserPW fields.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OTRS | =2.4.0-beta6 | |
OTRS | =2.4.0-beta5 | |
OTRS | =2.0.0-beta4 | |
OTRS | =2.0.0-beta2 | |
OTRS | =2.3.0-beta2 | |
OTRS | =2.4.1 | |
OTRS | =2.1.3 | |
OTRS | =2.2.4 | |
OTRS | =2.2.5 | |
OTRS | =2.4.10 | |
OTRS | =1.0.2 | |
OTRS | =2.4.5 | |
OTRS | =2.3.5 | |
OTRS | =2.1.8 | |
OTRS | =1.1.1 | |
OTRS | =2.3.0-beta1 | |
OTRS | =0.5-beta1 | |
OTRS | =1.2.0-beta2 | |
OTRS | =1.2.0-beta3 | |
OTRS | =1.3.1 | |
OTRS | =2.2.0-beta3 | |
OTRS | =2.0.0-beta5 | |
OTRS | =2.1.5 | |
OTRS | =2.3.4 | |
OTRS | =2.1.2 | |
OTRS | =3.0.2 | |
OTRS | =0.5-beta4 | |
OTRS | =0.5-beta7 | |
OTRS | =2.4.6 | |
OTRS | =1.3.0-beta4 | |
OTRS | =2.2.0-beta4 | |
OTRS | =2.4.0-beta3 | |
OTRS | =2.0.3 | |
OTRS | =1.1.0-rc1 | |
OTRS | =3.0.0-beta1 | |
OTRS | =1.1-rc1 | |
OTRS | =0.5-beta2 | |
OTRS | =2.1.0-beta1 | |
OTRS | =2.3.0-beta4 | |
OTRS | =1.2.1 | |
OTRS | =3.0.1 | |
OTRS | <=3.0.5 | |
OTRS | =2.2.0-beta1 | |
OTRS | =2.2.6 | |
OTRS | =2.4.9 | |
OTRS | =2.3.3 | |
OTRS | =2.0.0 | |
OTRS | =1.1.4 | |
OTRS | =0.5-beta6 | |
OTRS | =2.2.0-beta2 | |
OTRS | =0.5-beta3 | |
OTRS | =3.0.0-beta3 | |
OTRS | =3.0.0-beta6 | |
OTRS | =3.0.4 | |
OTRS | =1.2.3 | |
OTRS | =2.4.0-beta2 | |
OTRS | =2.2.2 | |
OTRS | =2.4.3 | |
OTRS | =2.3.1 | |
OTRS | =1.0.1 | |
OTRS | =1.2.4 | |
OTRS | =2.0.0-beta1 | |
OTRS | =2.0.5 | |
OTRS | =1.1.2 | |
OTRS | =2.2.0-rc1 | |
OTRS | =0.5-beta8 | |
OTRS | =2.2.9 | |
OTRS | =3.0.0-beta2 | |
OTRS | =2.1.6 | |
OTRS | =1.3.2 | |
OTRS | =2.1.0-beta2 | |
OTRS | =1.2.2 | |
OTRS | =2.4.0-beta4 | |
OTRS | =1.0-rc1 | |
OTRS | =1.3.0-beta1 | |
OTRS | =2.4.4 | |
OTRS | =2.1.7 | |
OTRS | =2.4.2 | |
OTRS | =2.0.4 | |
OTRS | =1.3.0-beta3 | |
OTRS | =3.0.0-beta4 | |
OTRS | =1.3.0-beta2 | |
OTRS | =2.1.9 | |
OTRS | =2.2.7 | |
OTRS | =2.2.1 | |
OTRS | =1.1.3 | |
OTRS | =2.1.4 | |
OTRS | =2.4.8 | |
OTRS | =1.0.0 | |
OTRS | =2.3.2 | |
OTRS | =2.3.0-rc1 | |
OTRS | =2.1.1 | |
OTRS | =2.0.2 | |
OTRS | =2.0.1 | |
OTRS | =2.4.0-beta1 | |
OTRS | =1.1.0-rc2 | |
OTRS | =3.0.3 | |
OTRS | =2.2.3 | |
OTRS | =2.4.7 | |
OTRS | =2.3.0-beta3 | |
OTRS | =2.0.0-beta6 | |
OTRS | =1.3.3 | |
OTRS | =2.2.8 | |
OTRS | =1.0-rc2 | |
OTRS | =3.0.0-beta5 | |
OTRS | =2.3.6 | |
OTRS | =1.0-rc3 | |
OTRS | =1.2.0-beta1 | |
OTRS | =3.0.0-beta7 | |
OTRS | =0.5-beta5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1433 is considered a high-severity vulnerability due to the exposure of cleartext credentials in session data.
To fix CVE-2011-1433, upgrade to OTRS version 3.0.6 or later, where this issue has been addressed.
CVE-2011-1433 can be exploited by context-dependent attackers who can access the database and read sensitive information.
CVE-2011-1433 affects various OTRS versions prior to 3.0.6, including multiple beta releases.
CVE-2011-1433 involves the AgentInterface and CustomerInterface components of the Open Ticket Request System.