CVE-2014-1471: SQL Injection
Published Feb 4, 2014
·Updated
SQL injection vulnerability in the StateGetStatesByType function in Kernel/System/State.pm in Open Ticket Request System (OTRS) 3.1.x before 3.1.19, 3.2.x before 3.2.14, and 3.3.x before 3.3.4 allows remote attackers to execute arbitrary SQL commands via vectors related to a ticket search URL.
Affected Software
45 affected components
OTRS OTRS=3.3.0
OTRS OTRS=3.3.0-beta1
OTRS OTRS=3.3.0-beta2
OTRS OTRS=3.3.0-beta3
OTRS OTRS=3.3.0-beta4
OTRS OTRS=3.3.0-beta5
OTRS OTRS=3.3.0-rc1
OTRS OTRS=3.3.1
OTRS OTRS=3.3.2
OTRS OTRS=3.3.3
OTRS OTRS=3.2.0
OTRS OTRS=3.2.0-beta1
OTRS OTRS=3.2.0-beta2
OTRS OTRS=3.2.0-beta3
OTRS OTRS=3.2.0-beta4
OTRS OTRS=3.2.0-beta5
OTRS OTRS=3.2.0-rc1
OTRS OTRS=3.2.1
OTRS OTRS=3.2.2
OTRS OTRS=3.2.3
OTRS OTRS=3.2.4
OTRS OTRS=3.2.5
OTRS OTRS=3.2.6
OTRS OTRS=3.2.7
OTRS OTRS=3.2.8
OTRS OTRS=3.2.9
OTRS OTRS=3.2.10
OTRS OTRS=3.1.0
OTRS OTRS=3.1.1
OTRS OTRS=3.1.2
OTRS OTRS=3.1.3
OTRS OTRS=3.1.4
OTRS OTRS=3.1.5
OTRS OTRS=3.1.6
OTRS OTRS=3.1.7
OTRS OTRS=3.1.8
OTRS OTRS=3.1.9
OTRS OTRS=3.1.10
OTRS OTRS=3.1.11
OTRS OTRS=3.1.13
OTRS OTRS=3.1.14
OTRS OTRS=3.1.15
OTRS OTRS=3.1.16
OTRS OTRS=3.1.17
OTRS OTRS=3.1.18
Remediation
Event History
Feb 4, 2014
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·09:55 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-1471?
The severity of CVE-2014-1471 is considered high due to its potential for remote attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2014-1471?
To fix CVE-2014-1471, upgrade to OTRS version 3.1.19, 3.2.14, or 3.3.4 or later.
3
Which versions of OTRS are affected by CVE-2014-1471?
CVE-2014-1471 affects OTRS versions 3.1.x before 3.1.19, 3.2.x before 3.2.14, and 3.3.x before 3.3.4.
4
What type of vulnerability is CVE-2014-1471?
CVE-2014-1471 is an SQL injection vulnerability.
5
Can CVE-2014-1471 be exploited through a web interface?
Yes, CVE-2014-1471 can be exploited by manipulating ticket search URLs through a web interface.