CVE-2019-12497: Debian Linux

Medium severity, CVSS 5.3. EPSS: 1.8% chance of exploitation in the next 30 days.

An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.8, Community Edition 6.0.x through 6.0.19, and Community Edition 5.0.x through 5.0.36. In the customer or external frontend, personal information of agents (e.g., Name and mail address) can be disclosed in external notes.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Otrs Otrs: from 5.0.0, up to and including 5.0.36; from 6.0.0, up to and including 6.0.19; from 7.0.0, up to and including 7.0.8

Published 2019-06-17. Last modified 2026-06-17.