OTRS Session Hijacking Vulnerability Due to Missing Cookie Attributes

Vulnerability

A session hijacking vulnerability exists in OTRS Application Server and reverse proxy settings, caused by missing attributes for sensitive cookie settings in HTTPS sessions. This issue affects OTRS versions 7.0.X, 8.0.X, 2023.X, and 2024.X.

Impact

Exploitation of this vulnerability allows for session hijacking, where an attacker can take over a user's session.

Remediation

Users are advised to update to OTRS version 2025.1.x. Note that there will be no patches for OTRS 7.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
1.3
exploitability
7.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.