CVE-2017-16854: Infoleak
In Open Ticket Request System (OTRS) through 3.3.20, 4 through 4.0.26, 5 through 5.0.24, and 6 through 6.0.1, an attacker who is logged in as a customer can use the ticket search form to disclose internal article information of their customer tickets.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-16854?
The severity of CVE-2017-16854 is rated as medium with a score of 6.5.
How do I fix CVE-2017-16854?
To fix CVE-2017-16854, upgrade the OTRS software to a version above 6.0.1 or apply the relevant security patches.
What systems are affected by CVE-2017-16854?
CVE-2017-16854 affects OTRS versions 3.3.20, 4.0.26, 5.0.24, and 6.0.1 and earlier versions.
What is the nature of the vulnerability described in CVE-2017-16854?
CVE-2017-16854 allows logged-in customer attackers to disclose internal article information of their customer tickets.
Who should be concerned about CVE-2017-16854?
Organizations using affected versions of OTRS should be concerned about CVE-2017-16854 and take action to mitigate the vulnerability.