CVE-2019-12497: Infoleak
An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.8, Community Edition 6.0.x through 6.0.19, and Community Edition 5.0.x through 5.0.36. In the customer or external frontend, personal information of agents (e.g., Name and mail address) can be disclosed in external notes.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-12497.
What versions of Open Ticket Request System (OTRS) are affected?
Open Ticket Request System (OTRS) versions 5.0.0 through 5.0.36, 6.0.0 through 6.0.19, and 7.0.0 through 7.0.8 are affected.
What is the severity of CVE-2019-12497?
The severity of CVE-2019-12497 is medium with a CVSS score of 5.3.
How can personal information of agents be disclosed in external notes?
In the customer or external frontend, personal information of agents such as name and email address can be disclosed in external notes.
Where can I find more information about CVE-2019-12497?
You can find more information about CVE-2019-12497 at the following references: [Reference 1](http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00038.html), [Reference 2](http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00066.html), [Reference 3](http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00077.html).