CVE-2017-9324: High severity OTRS OTRS vulnerability

Published Jun 12, 2017
·
Updated

In Open Ticket Request System (OTRS) 3.3.x through 3.3.16, 4.x through 4.0.23, and 5.x through 5.0.19, an attacker with agent permission is capable of opening a specific URL in a browser to gain administrative privileges / full access. Afterward, all system settings can be read and changed. The URLs in question contain index.pl?Action=Installer with ;Subaction=Intro or ;Subaction=Start or ;Subaction=System appended at the end.

Affected Software

5 affected components
OTRS OTRS>=3.3.0<=3.3.16
OTRS OTRS>=4.0.0<=4.0.23
OTRS OTRS>=5.0.0<=5.0.19
Debian Debian Linux=8.0
Debian Debian Linux=9.0

Event History

Jun 12, 2017
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2017-9324?

CVE-2017-9324 is considered a critical vulnerability due to the potential for unauthorized administrative access.

2

How do I fix CVE-2017-9324?

To fix CVE-2017-9324, upgrade OTRS to a version that is not affected, specifically versions 3.3.17, 4.0.24, or 5.0.20 and above.

3

Who is affected by CVE-2017-9324?

CVE-2017-9324 affects users of Open Ticket Request System (OTRS) versions 3.3.x to 3.3.16, 4.x to 4.0.23, and 5.x to 5.0.19.

4

What versions of OTRS are vulnerable to CVE-2017-9324?

Versions of OTRS vulnerable to CVE-2017-9324 include any from 3.3.0 through 3.3.16, 4.0.0 through 4.0.23, and 5.0.0 through 5.0.19.

5

What impact does CVE-2017-9324 have on system security?

CVE-2017-9324 allows an attacker with agent permissions to gain full administrative access, compromising the system's integrity and confidentiality.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203