CVE-2017-16921: OS Command Injection
In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.26, an attacker who is logged into OTRS as an agent can manipulate form parameters (related to PGP) and execute arbitrary shell commands with the permissions of the OTRS or web server user.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-16921?
CVE-2017-16921 is classified as a high severity vulnerability due to its potential to allow attackers to execute arbitrary shell commands.
How do I fix CVE-2017-16921?
To fix CVE-2017-16921, upgrade OTRS to version 6.0.16-2 or higher, or 5.0.25 or higher, depending on your current version.
Which versions of OTRS are affected by CVE-2017-16921?
The affected versions include OTRS 6.0.x up to and including 6.0.1, 5.0.x up to and including 5.0.24, and 4.0.x up to and including 4.0.26.
Can an attacker exploit CVE-2017-16921 remotely?
No, the attacker must be logged into OTRS as an agent to exploit CVE-2017-16921.
Is CVE-2017-16921 related to PGP functionality in OTRS?
Yes, CVE-2017-16921 involves the manipulation of form parameters related to PGP in OTRS.