CVE-2017-9324
Last modified
CVE-2017-9324 is a vulnerability of currently unknown severity. In Open Ticket Request System (OTRS) 3.3.x through 3.3.16, 4.x through 4.0.23, and 5.x through 5.0.19, an attacker with agent permission is capable of opening a specific URL in a browser to gain administrative privileges / full access. Afterward, all system settings can be read and changed. EPSS estimates a 2.35% chance of exploitation in the next 30 days.
Description
In Open Ticket Request System (OTRS) 3.3.x through 3.3.16, 4.x through 4.0.23, and 5.x through 5.0.19, an attacker with agent permission is capable of opening a specific URL in a browser to gain administrative privileges / full access. Afterward, all system settings can be read and changed. The URLs in question contain index.pl?Action=Installer with ;Subaction=Intro or ;Subaction=Start or ;Subaction=System appended at the end.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Otrs | Otrs | >= 3.3.0, <= 3.3.16 |
| Otrs | Otrs | >= 4.0.0, <= 4.0.23 |
| Otrs | Otrs | >= 5.0.0, <= 5.0.19 |
| Debian | Debian Linux | 8.0 |
| Debian | Debian Linux | 9.0 |
References
- http://www.debian.org/security/2017/dsa-3876Third Party Advisory
- https://packetstormsecurity.com/files/142862/OTRS-Install-Dialog-Disclosure.htmlMailing List, Third Party Advisory, VDB Entry
- http://www.debian.org/security/2017/dsa-3876Third Party Advisory
- https://packetstormsecurity.com/files/142862/OTRS-Install-Dialog-Disclosure.htmlMailing List, Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-9324?
How severe is CVE-2017-9324?
How do I fix CVE-2017-9324?
Are you affected by CVE-2017-9324?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
