CVE-2019-12497

An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.8, Community Edition 6.0.x through 6.0.19, and Community Edition 5.0.x through 5.0.36. In the customer or external frontend, personal information of agents (e.g., Name and mail address) can be disclosed in external notes.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:otrs:otrs:*:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:*:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

History

31 Aug 2023, 03:15

Type Values Removed Values Added
References
  • (MLIST) https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html -

20 Jan 2023, 16:14

Type Values Removed Values Added
References (SUSE) http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00066.html - (SUSE) http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00066.html - Broken Link
References (SUSE) http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00077.html - (SUSE) http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00077.html - Broken Link
References (SUSE) http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00038.html - (SUSE) http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00038.html - Broken Link

Information

Published : 2019-06-17 17:15

Updated : 2023-12-10 12:59


NVD link : CVE-2019-12497

Mitre link : CVE-2019-12497

CVE.ORG link : CVE-2019-12497


JSON object : View

Products Affected

otrs

  • otrs

debian

  • debian_linux
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor