OTRS Application Server Session Hijacking Vulnerability Due to Insecure Cookie Attributes

Vulnerability

A session hijacking vulnerability has been identified in OTRS Application Server. This issue arises from missing attributes in cookie settings for HTTPS sessions, allowing authentication cookies to be sent from a potentially malicious website to an OTRS endpoint. As a result, unauthorized read operations could be performed. The vulnerability affects OTRS versions 7.0.X, 8.0.X, 2023.X, 2024.X, and 2025.x prior to 2025.1.2.

Impact

Exploitation of this vulnerability allows for session hijacking, where an attacker can impersonate a user by stealing their authentication cookie.

Remediation

Users are advised to update to OTRS version 2025.2.x. Note that there will be no patches for OTRS 7.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
1.3
exploitability
7.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.