CVE-2022-4427

EUVD-2022-51772
Improper Input Validation vulnerability in OTRS AG OTRS, OTRS AG ((OTRS)) Community Edition allows SQL Injection via TicketSearch Webservice
This issue affects OTRS: from 7.0.1 before 7.0.40 Patch 1, from 8.0.1 before 8.0.28 Patch 1; ((OTRS)) Community Edition: from 6.0.1 through 6.0.34.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
OTRSCNA
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 43%
Affected Products (NVD)
VendorProductVersion
otrsotrs
6.0.1 ≤
𝑥
≤ 6.0.34
otrsotrs
7.0.1 ≤
𝑥
< 7.0.40
otrsotrs
8.0.1 ≤
𝑥
< 8.0.28
otrsotrs
7.0.40
otrsotrs
8.0.28
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
otrs2
bullseye/non-free
vulnerable
znuny
bookworm/non-free
6.5.1-1
fixed
bullseye
no-dsa
sid/non-free
6.5.11-1
fixed
trixie/non-free
6.5.11-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
znuny
bionic
dne
focal
dne
jammy
dne
kinetic
ignored
lunar
not-affected
trusty
ignored
xenial
ignored