Specially crafted string in OTRS system configuration can allow the execution of any system command.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3551-1 | otrs2 security update |
EUVD |
EUVD-2021-22732 | Specially crafted string in OTRS system configuration can allow the execution of any system command. |
Fixes
Solution
Update to OTRS 8.0.20, OTRS 7.0.33. Update to OTRSSTORM 8.0.12, OTRS 7.0.28. Update to SystemMonitoring 8.0.9, OTRS 7.0.19.
Workaround
No workaround given by the vendor.
References
History
Tue, 17 Sep 2024 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authenticated remote code execution | Authenticated remote code execution |
Status: PUBLISHED
Assigner: OTRS
Published:
Updated: 2024-09-17T02:00:46.987Z
Reserved: 2021-07-01T00:00:00
Link: CVE-2021-36100
No data.
Status : Modified
Published: 2022-03-21T10:15:07.777
Modified: 2024-11-21T06:13:09.263
Link: CVE-2021-36100
No data.
OpenCVE Enrichment
No data.
Debian DLA
EUVD