CVE-2017-17476: Debian Linux

High severity, CVSS 8.8. EPSS: 2.2% chance of exploitation in the next 30 days.

Open Ticket Request System (OTRS) 4.0.x before 4.0.28, 5.0.x before 5.0.26, and 6.0.x before 6.0.3, when cookie support is disabled, might allow remote attackers to hijack web sessions and consequently gain privileges via a crafted email.

Affected products

  • Debian Debian Linux: version 7.0 only; version 8.0 only; version 9.0 only
  • Otrs Otrs: from 4.0.0, before 4.0.28 (fixed in 4.0.28); from 5.0.0, before 5.0.26 (fixed in 5.0.26); from 6.0.0, before 6.0.3 (fixed in 6.0.3)

Published 2017-12-20. Last modified 2026-06-17.