Specially crafted string in OTRS system configuration can allow the execution of any system command.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-3551-1 otrs2 security update
EUVD EUVD EUVD-2021-22732 Specially crafted string in OTRS system configuration can allow the execution of any system command.
Fixes

Solution

Update to OTRS 8.0.20, OTRS 7.0.33. Update to OTRSSTORM 8.0.12, OTRS 7.0.28. Update to SystemMonitoring 8.0.9, OTRS 7.0.19.


Workaround

No workaround given by the vendor.

History

Tue, 17 Sep 2024 02:15:00 +0000

Type Values Removed Values Added
Title Authenticated remote code execution Authenticated remote code execution

cve-icon MITRE

Status: PUBLISHED

Assigner: OTRS

Published:

Updated: 2024-09-17T02:00:46.987Z

Reserved: 2021-07-01T00:00:00

Link: CVE-2021-36100

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-03-21T10:15:07.777

Modified: 2024-11-21T06:13:09.263

Link: CVE-2021-36100

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.