CVE-2017-14635
Debian Security Advisory 4021-1
Severity Score
8.8
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
In Open Ticket Request System (OTRS) 3.3.x before 3.3.18, 4.x before 4.0.25, and 5.x before 5.0.23, remote authenticated users can leverage statistics-write permissions to gain privileges via code injection.
En OTRS (Open Ticket Request System) en versiones 3.3.x anteriores a la 3.3.18, 4.x anteriores a la 4.0.25 y 5.x anteriores a la 5.0.23, los usuarios autenticados remotos pueden utilizar los permisos de escritura de estadísticas para obtener privilegios mediante la inyección de código.
It was discovered that missing input validation in the Open Ticket Request System could result in privilege escalation by an agent with write permissions for statistics.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2017-09-21 CVE Reserved
- 2017-09-21 CVE Published
- 2024-08-05 CVE Updated
- 2025-04-07 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.debian.org/security/2017/dsa-4021 | 2019-10-03 | |
https://www.otrs.com/security-advisory-2017-04-security-update-otrs-versions | 2019-10-03 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.3.0 Search vendor "Otrs" for product "Otrs" and version "3.3.0" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.3.0 Search vendor "Otrs" for product "Otrs" and version "3.3.0" | beta1 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.3.0 Search vendor "Otrs" for product "Otrs" and version "3.3.0" | beta2 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.3.0 Search vendor "Otrs" for product "Otrs" and version "3.3.0" | beta3 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.3.0 Search vendor "Otrs" for product "Otrs" and version "3.3.0" | beta4 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.3.0 Search vendor "Otrs" for product "Otrs" and version "3.3.0" | beta5 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.3.0 Search vendor "Otrs" for product "Otrs" and version "3.3.0" | rc1 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.3.1 Search vendor "Otrs" for product "Otrs" and version "3.3.1" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.3.2 Search vendor "Otrs" for product "Otrs" and version "3.3.2" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.3.3 Search vendor "Otrs" for product "Otrs" and version "3.3.3" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.3.4 Search vendor "Otrs" for product "Otrs" and version "3.3.4" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.3.5 Search vendor "Otrs" for product "Otrs" and version "3.3.5" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.3.6 Search vendor "Otrs" for product "Otrs" and version "3.3.6" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.3.7 Search vendor "Otrs" for product "Otrs" and version "3.3.7" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.3.8 Search vendor "Otrs" for product "Otrs" and version "3.3.8" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.3.9 Search vendor "Otrs" for product "Otrs" and version "3.3.9" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.3.10 Search vendor "Otrs" for product "Otrs" and version "3.3.10" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.3.11 Search vendor "Otrs" for product "Otrs" and version "3.3.11" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.3.12 Search vendor "Otrs" for product "Otrs" and version "3.3.12" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.3.13 Search vendor "Otrs" for product "Otrs" and version "3.3.13" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.3.14 Search vendor "Otrs" for product "Otrs" and version "3.3.14" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.3.15 Search vendor "Otrs" for product "Otrs" and version "3.3.15" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.3.16 Search vendor "Otrs" for product "Otrs" and version "3.3.16" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 3.3.17 Search vendor "Otrs" for product "Otrs" and version "3.3.17" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 4.0.0 Search vendor "Otrs" for product "Otrs" and version "4.0.0" | beta1 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 4.0.0 Search vendor "Otrs" for product "Otrs" and version "4.0.0" | beta2 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 4.0.0 Search vendor "Otrs" for product "Otrs" and version "4.0.0" | beta3 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 4.0.0 Search vendor "Otrs" for product "Otrs" and version "4.0.0" | beta4 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 4.0.0 Search vendor "Otrs" for product "Otrs" and version "4.0.0" | beta5 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 4.0.0 Search vendor "Otrs" for product "Otrs" and version "4.0.0" | rc1 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 4.0.1 Search vendor "Otrs" for product "Otrs" and version "4.0.1" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 4.0.2 Search vendor "Otrs" for product "Otrs" and version "4.0.2" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 4.0.3 Search vendor "Otrs" for product "Otrs" and version "4.0.3" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 4.0.4 Search vendor "Otrs" for product "Otrs" and version "4.0.4" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 4.0.5 Search vendor "Otrs" for product "Otrs" and version "4.0.5" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 4.0.6 Search vendor "Otrs" for product "Otrs" and version "4.0.6" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 4.0.7 Search vendor "Otrs" for product "Otrs" and version "4.0.7" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 4.0.8 Search vendor "Otrs" for product "Otrs" and version "4.0.8" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 4.0.9 Search vendor "Otrs" for product "Otrs" and version "4.0.9" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 4.0.10 Search vendor "Otrs" for product "Otrs" and version "4.0.10" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 4.0.11 Search vendor "Otrs" for product "Otrs" and version "4.0.11" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 4.0.12 Search vendor "Otrs" for product "Otrs" and version "4.0.12" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 4.0.13 Search vendor "Otrs" for product "Otrs" and version "4.0.13" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 4.0.14 Search vendor "Otrs" for product "Otrs" and version "4.0.14" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 4.0.15 Search vendor "Otrs" for product "Otrs" and version "4.0.15" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 4.0.16 Search vendor "Otrs" for product "Otrs" and version "4.0.16" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 4.0.17 Search vendor "Otrs" for product "Otrs" and version "4.0.17" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 4.0.18 Search vendor "Otrs" for product "Otrs" and version "4.0.18" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 4.0.19 Search vendor "Otrs" for product "Otrs" and version "4.0.19" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 4.0.20 Search vendor "Otrs" for product "Otrs" and version "4.0.20" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 4.0.21 Search vendor "Otrs" for product "Otrs" and version "4.0.21" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 4.0.22 Search vendor "Otrs" for product "Otrs" and version "4.0.22" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 4.0.23 Search vendor "Otrs" for product "Otrs" and version "4.0.23" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 4.0.24 Search vendor "Otrs" for product "Otrs" and version "4.0.24" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 5.0.0 Search vendor "Otrs" for product "Otrs" and version "5.0.0" | beta1 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 5.0.0 Search vendor "Otrs" for product "Otrs" and version "5.0.0" | beta2 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 5.0.0 Search vendor "Otrs" for product "Otrs" and version "5.0.0" | beta3 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 5.0.0 Search vendor "Otrs" for product "Otrs" and version "5.0.0" | beta4 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 5.0.0 Search vendor "Otrs" for product "Otrs" and version "5.0.0" | beta5 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 5.0.0 Search vendor "Otrs" for product "Otrs" and version "5.0.0" | rc1 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 5.0.1 Search vendor "Otrs" for product "Otrs" and version "5.0.1" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 5.0.2 Search vendor "Otrs" for product "Otrs" and version "5.0.2" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 5.0.3 Search vendor "Otrs" for product "Otrs" and version "5.0.3" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 5.0.4 Search vendor "Otrs" for product "Otrs" and version "5.0.4" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 5.0.5 Search vendor "Otrs" for product "Otrs" and version "5.0.5" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 5.0.6 Search vendor "Otrs" for product "Otrs" and version "5.0.6" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 5.0.7 Search vendor "Otrs" for product "Otrs" and version "5.0.7" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 5.0.8 Search vendor "Otrs" for product "Otrs" and version "5.0.8" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 5.0.9 Search vendor "Otrs" for product "Otrs" and version "5.0.9" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 5.0.10 Search vendor "Otrs" for product "Otrs" and version "5.0.10" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 5.0.11 Search vendor "Otrs" for product "Otrs" and version "5.0.11" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 5.0.12 Search vendor "Otrs" for product "Otrs" and version "5.0.12" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 5.0.13 Search vendor "Otrs" for product "Otrs" and version "5.0.13" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 5.0.14 Search vendor "Otrs" for product "Otrs" and version "5.0.14" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 5.0.15 Search vendor "Otrs" for product "Otrs" and version "5.0.15" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 5.0.16 Search vendor "Otrs" for product "Otrs" and version "5.0.16" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 5.0.17 Search vendor "Otrs" for product "Otrs" and version "5.0.17" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 5.0.18 Search vendor "Otrs" for product "Otrs" and version "5.0.18" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 5.0.19 Search vendor "Otrs" for product "Otrs" and version "5.0.19" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 5.0.20 Search vendor "Otrs" for product "Otrs" and version "5.0.20" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 5.0.21 Search vendor "Otrs" for product "Otrs" and version "5.0.21" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 5.0.22 Search vendor "Otrs" for product "Otrs" and version "5.0.22" | - |
Affected
|