First published: Mon Jun 17 2019(Updated: )
An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.8, Community Edition 6.0.x through 6.0.19, and Community Edition 5.0.x through 5.0.36. In the customer or external frontend, personal information of agents (e.g., Name and mail address) can be disclosed in external notes.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Otrs Otrs | >=5.0.0<=5.0.36 | |
Otrs Otrs | >=6.0.0<=6.0.19 | |
Otrs Otrs | >=7.0.0<=7.0.8 | |
Debian Debian Linux | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2019-12497.
Open Ticket Request System (OTRS) versions 5.0.0 through 5.0.36, 6.0.0 through 6.0.19, and 7.0.0 through 7.0.8 are affected.
The severity of CVE-2019-12497 is medium with a CVSS score of 5.3.
In the customer or external frontend, personal information of agents such as name and email address can be disclosed in external notes.
You can find more information about CVE-2019-12497 at the following references: [Reference 1](http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00038.html), [Reference 2](http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00066.html), [Reference 3](http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00077.html).