Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.112718
Kategorie:Web application abuses
Titel:OTRS 5.0.x < 5.0.42, 6.0.x < 6.0.27, 7.0.x < 7.0.16 Multiple Vulnerabilities
Zusammenfassung:OTRS is prone to multiple vulnerabilities.
Beschreibung:Summary:
OTRS is prone to multiple vulnerabilities.

Vulnerability Insight:
OTRS is prone to multiple vulnerabilities:

- Autocomplete in the form login screens (CVE-2020-1769)

- Information disclosure in support bundle files (CVE-2020-1770)

- Possible XSS in Customer user address book (CVE-2020-1771)

- Information Disclosure (CVE-2020-1772)

- Session / Password / Password token leak (CVE-2020-1773)

Affected Software/OS:
OTRS 5.0.x through 5.0.41, 6.0.x through 6.0.26 and 7.0.x through 7.0.15.

Solution:
Update to version 5.0.42, 6.0.27, 7.0.16 or later.

CVSS Score:
5.5

CVSS Vector:
AV:N/AC:L/Au:S/C:P/I:P/A:N

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2020-1769
https://otrs.com/release-notes/otrs-security-advisory-2020-06/
SuSE Security Announcement: openSUSE-SU-2020:0551 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00038.html
SuSE Security Announcement: openSUSE-SU-2020:1475 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00066.html
SuSE Security Announcement: openSUSE-SU-2020:1509 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00077.html
Common Vulnerability Exposure (CVE) ID: CVE-2020-1770
https://otrs.com/release-notes/otrs-security-advisory-2020-07/
https://lists.debian.org/debian-lts-announce/2020/05/msg00000.html
Common Vulnerability Exposure (CVE) ID: CVE-2020-1771
https://otrs.com/release-notes/otrs-security-advisory-2020-08/
Common Vulnerability Exposure (CVE) ID: CVE-2020-1772
https://otrs.com/release-notes/otrs-security-advisory-2020-09/
Common Vulnerability Exposure (CVE) ID: CVE-2020-1773
https://otrs.com/release-notes/otrs-security-advisory-2020-10/
CopyrightCopyright (C) 2020 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.