CVE-2021-36100: Authenticated remote code execution
Published Mar 21, 2022
·Updated
Specially crafted string in OTRS system configuration can allow the execution of any system command.
Affected Software
6 affected components
OTRS OTRS<7.0.28
OTRS OTRS>=7.0.30<7.0.33
OTRS OTRS>=8.0.0<8.0.21
OTRS OTRS ITSM<7.0.19
OTRS OTRS ITSM>=8.0.0<8.0.28
OTRS Otrs Storm<8.0.12
Remediation
Information
Update to OTRS 8.0.20, OTRS 7.0.33. Update to OTRSSTORM 8.0.12, OTRS 7.0.28. Update to SystemMonitoring 8.0.9, OTRS 7.0.19.
Event History
Mar 21, 2022
CVE Published
via MITRE·09:15 AM
Data Sourced
via MITRE·09:15 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-36100?
CVE-2021-36100 is a vulnerability in the OTRS system configuration that allows the execution of any system command.
2
How does CVE-2021-36100 affect OTRS?
CVE-2021-36100 affects OTRS versions 7.0.28 to 7.0.33 and versions 8.0.0 to 8.0.21, as well as OTRS ITSM versions 7.0.19 to 8.0.28 and OTRS Storm version 8.0.12.
3
What is the severity of CVE-2021-36100?
CVE-2021-36100 has a severity rating of 8.8 (critical).
4
How can I fix CVE-2021-36100?
To fix CVE-2021-36100, OTRS users should update to the latest patched version of the software.
5
Where can I find more information about CVE-2021-36100?
More information about CVE-2021-36100 can be found in the Debian LTS announce and the OTRS security advisory.