CVE-2020-1778

MEDIUM

OTRS < 8.0.9 - Improper Authentication via Multiple Backends

Title source: llm
STIX 2.1

Description

When OTRS uses multiple backends for user authentication (with LDAP), agents are able to login even if the account is set to invalid. This issue affects OTRS; 8.0.9 and prior versions.

References (1)

Core 1
Core References
Release Notes, Vendor Advisory x_refsource_confirm
https://otrs.com/release-notes/otrs-security-advisory-2020-16/

Scores

CVSS v3 4.1
EPSS 0.0064
EPSS Percentile 46.2%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

Details

CWE
CWE-287
Status published
Products (1)
otrs/otrs < 8.0.9
Published Nov 23, 2020
Tracked Since Feb 18, 2026