CVE-2017-17476: Infoleak
Published Dec 19, 2017
·Updated
Open Ticket Request System (OTRS) 4.0.x before 4.0.28, 5.0.x before 5.0.26, and 6.0.x before 6.0.3, when cookie support is disabled, might allow remote attackers to hijack web sessions and consequently gain privileges via a crafted email.
Affected Software
7 affected componentsFixes available
debian/otrs2
6.0.16-26.0.16-2+deb10u16.0.32-6
OTRS OTRS>=4.0.0<4.0.28
OTRS OTRS>=5.0.0<5.0.26
OTRS OTRS>=6.0.0<6.0.3
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Remediation
Event History
Dec 19, 2017
Data Sourced
08:24 PM
SeverityAffected Software
Dec 20, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-17476?
CVE-2017-17476 is considered a high severity vulnerability due to its potential for remote session hijacking.
2
How do I fix CVE-2017-17476?
To fix CVE-2017-17476, upgrade to OTRS version 4.0.28, 5.0.26, or 6.0.3 or later.
3
Which versions of OTRS are affected by CVE-2017-17476?
CVE-2017-17476 affects OTRS versions prior to 4.0.28, 5.0.26, and 6.0.3.
4
Can CVE-2017-17476 allow privilege escalation?
Yes, CVE-2017-17476 can allow remote attackers to gain elevated privileges through session hijacking.
5
Is cookie support a factor in CVE-2017-17476?
Yes, CVE-2017-17476 exploits the vulnerability when cookie support is disabled.