CVE-2017-14635
published 2017-09-21CVE-2017-14635: In Open Ticket Request System (OTRS) 3.3.x before 3.3.18, 4.x before 4.0.25, and 5.x before 5.0.23, remote authenticated users can leverage statistics-write…
PriorityP350high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
1.92%
77.4th percentile
In Open Ticket Request System (OTRS) 3.3.x before 3.3.18, 4.x before 4.0.25, and 5.x before 5.0.23, remote authenticated users can leverage statistics-write permissions to gain privileges via code injection.
Affected
67 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | otrs2 | < otrs2 5.0.23-1 (bullseye) | otrs2 5.0.23-1 (bullseye) |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7r29-5mg8-c6rc: In Open Ticket Request System (OTRS) 3
ghsa_unreviewed·2022-05-13
CVE-2017-14635 [HIGH] CWE-20 GHSA-7r29-5mg8-c6rc: In Open Ticket Request System (OTRS) 3
In Open Ticket Request System (OTRS) 3.3.x before 3.3.18, 4.x before 4.0.25, and 5.x before 5.0.23, remote authenticated users can leverage statistics-write permissions to gain privileges via code injection.
OSV
CVE-2017-14635: In Open Ticket Request System (OTRS) 3
osv·2017-09-21·CVSS 8.8
CVE-2017-14635 [HIGH] CVE-2017-14635: In Open Ticket Request System (OTRS) 3
In Open Ticket Request System (OTRS) 3.3.x before 3.3.18, 4.x before 4.0.25, and 5.x before 5.0.23, remote authenticated users can leverage statistics-write permissions to gain privileges via code injection.
Debian
CVE-2017-14635: otrs2 - In Open Ticket Request System (OTRS) 3.3.x before 3.3.18, 4.x before 4.0.25, and...
vendor_debian·2017·CVSS 8.8
CVE-2017-14635 [HIGH] CVE-2017-14635: otrs2 - In Open Ticket Request System (OTRS) 3.3.x before 3.3.18, 4.x before 4.0.25, and...
In Open Ticket Request System (OTRS) 3.3.x before 3.3.18, 4.x before 4.0.25, and 5.x before 5.0.23, remote authenticated users can leverage statistics-write permissions to gain privileges via code injection.
Scope: local
bullseye: resolved (fixed in 5.0.23-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-09-21
Published