CVE-2020-1768

MEDIUM

OTRS 7.0.0-7.0.14 - Insufficient Session Expiration via Background Requests

Title source: llm
STIX 2.1

Description

The external frontend system uses numerous background calls to the backend. Each background request is treated as user activity so the SessionMaxIdleTime will not be reached. This issue affects: OTRS 7.0.x version 7.0.14 and prior versions.

References (1)

Core 1
Core References

Scores

CVSS v3 5.4
EPSS 0.0075
EPSS Percentile 49.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L

Details

CWE
CWE-613
Status published
Products (1)
otrs/otrs 7.0.0 - 7.0.14
Published Feb 07, 2020
Tracked Since Feb 18, 2026