Vulnerability Name: | CVE-2018-20800 (CCN-161677) | ||||||||||||||||||||||||||||||||||||
Assigned: | 2018-11-14 | ||||||||||||||||||||||||||||||||||||
Published: | 2018-11-14 | ||||||||||||||||||||||||||||||||||||
Updated: | 2019-03-18 | ||||||||||||||||||||||||||||||||||||
Summary: | An issue was discovered in Open Ticket Request System (OTRS) 5.0.31 and 6.0.13. Users updating to 6.0.13 (also patchlevel updates) or 5.0.31 (only major updates) will experience data loss in their agent preferences table. | ||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 6.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N) 5.7 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
4.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 5.5 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:P)
| ||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-20 | ||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Data Manipulation | ||||||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2018-20800 Source: MISC Type: Mitigation, Patch, Vendor Advisory https://community.otrs.com/security-advisory-2018-10-security-update-for-otrs-framework Source: CCN Type: OTRS Web site Security Advisory 2018-10: Security Update for OTRS Framework Source: XF Type: UNKNOWN otrs-cve201820800-weak-security(161677) Source: CCN Type: WhiteSource Vulnerability Database CVE-2018-20800 | ||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||
BACK |