|  |  | 
closedb();
?>
| Vulnerability CVE-2021-36097Published: 2021-10-18
 
 
	Type:
		| Description: |  
		| Agents are able to lock the ticket without the "Owner" permission. Once the ticket is locked, it could be moved to the queue where the agent has "rw" permissions and gain a full control. This issue affects: OTRS AG OTRS 8.0.x version: 8.0.16 and prior versions. |  
 CWE-732
				 CVSS2 => (AV:N/AC:L/Au:S/C:N/I:P/A:N)| CVSS Base Score | Impact Subscore | Exploitability Subscore |  
							| 4/10 | 2.9/10 | 8/10 | 
 
						| Exploit range | Attack complexity | Authentication |  
						| Remote | Low | Single time |  
						| Confidentiality impact | Integrity impact | Availability impact |  
						| None | Partial | None | 
 
|  References: |  
| https://otrs.com/release-notes/otrs-security-advisory-2021-20/ | 
 |  |  |  Copyright 2025, cxsecurity.com
  
     |  |  |