CVE-2019-9892: Debian Linux

Medium severity, CVSS 6.5. EPSS: 1.1% chance of exploitation in the next 30 days.

An issue was discovered in Open Ticket Request System (OTRS) 5.x through 5.0.34, 6.x through 6.0.17, and 7.x through 7.0.6. An attacker who is logged into OTRS as an agent user with appropriate permissions may try to import carefully crafted Report Statistics XML that will result in reading of arbitrary files on the OTRS filesystem.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Otrs Otrs: from 5.0.0, up to and including 5.0.34; from 6.0.0, up to and including 6.0.17; from 7.0.0, up to and including 7.0.6

Published 2019-05-22. Last modified 2026-06-17.