First published: Fri Dec 08 2017(Updated: )
In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.26, an attacker who is logged into OTRS as an agent can manipulate form parameters (related to PGP) and execute arbitrary shell commands with the permissions of the OTRS or web server user.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/otrs2 | 6.0.16-2 6.0.16-2+deb10u1 6.0.32-6 | |
OTRS | =4.0.1 | |
OTRS | =4.0.2 | |
OTRS | =4.0.3 | |
OTRS | =4.0.4 | |
OTRS | =4.0.5 | |
OTRS | =4.0.6 | |
OTRS | =4.0.7 | |
OTRS | =4.0.8 | |
OTRS | =4.0.9 | |
OTRS | =4.0.10 | |
OTRS | =4.0.11 | |
OTRS | =4.0.12 | |
OTRS | =4.0.13 | |
OTRS | =4.0.14 | |
OTRS | =4.0.15 | |
OTRS | =4.0.16 | |
OTRS | =4.0.17 | |
OTRS | =4.0.18 | |
OTRS | =4.0.19 | |
OTRS | =4.0.20 | |
OTRS | =4.0.21 | |
OTRS | =4.0.22 | |
OTRS | =4.0.23 | |
OTRS | =4.0.24 | |
OTRS | =4.0.25 | |
OTRS | =4.0.26 | |
OTRS | =5.0.0 | |
OTRS | =5.0.0-alpha1 | |
OTRS | =5.0.0-beta1 | |
OTRS | =5.0.0-beta2 | |
OTRS | =5.0.0-beta3 | |
OTRS | =5.0.0-beta4 | |
OTRS | =5.0.0-beta5 | |
OTRS | =5.0.0-rc1 | |
OTRS | =5.0.1 | |
OTRS | =5.0.2 | |
OTRS | =5.0.3 | |
OTRS | =5.0.4 | |
OTRS | =5.0.5 | |
OTRS | =5.0.6 | |
OTRS | =5.0.7 | |
OTRS | =5.0.8 | |
OTRS | =5.0.9 | |
OTRS | =5.0.10 | |
OTRS | =5.0.11 | |
OTRS | =5.0.12 | |
OTRS | =5.0.13 | |
OTRS | =5.0.14 | |
OTRS | =5.0.15 | |
OTRS | =5.0.16 | |
OTRS | =5.0.17 | |
OTRS | =5.0.18 | |
OTRS | =5.0.19 | |
OTRS | =5.0.20 | |
OTRS | =5.0.21 | |
OTRS | =5.0.22 | |
OTRS | =5.0.23 | |
OTRS | =5.0.24 | |
OTRS | =6.0.0 | |
OTRS | =6.0.0-alpha1 | |
OTRS | =6.0.0-beta1 | |
OTRS | =6.0.0-beta2 | |
OTRS | =6.0.0-beta3 | |
OTRS | =6.0.0-beta4 | |
OTRS | =6.0.0-beta5 | |
OTRS | =6.0.0-rc1 | |
OTRS | =6.0.1 | |
Debian GNU/Linux | =7.0 | |
Debian GNU/Linux | =8.0 | |
Debian GNU/Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-16921 is classified as a high severity vulnerability due to its potential to allow attackers to execute arbitrary shell commands.
To fix CVE-2017-16921, upgrade OTRS to version 6.0.16-2 or higher, or 5.0.25 or higher, depending on your current version.
The affected versions include OTRS 6.0.x up to and including 6.0.1, 5.0.x up to and including 5.0.24, and 4.0.x up to and including 4.0.26.
No, the attacker must be logged into OTRS as an agent to exploit CVE-2017-16921.
Yes, CVE-2017-16921 involves the manipulation of form parameters related to PGP in OTRS.