• Deutsch
  • English
  • Login
+49 (0)9427 68 39 000
OTOBO
  • SOFTWARE
    • Software | Overview
    • IT Service Management
    • Customer Service Management
    • Enterprise Service Management
    • Demo
    • Download
    • Documentation
  • SERVICES
    • Overview | Services
    • Consulting
    • Training
    • Customizing
    • OTRS Migration to OTOBO
    • Support
    • Managed Services
    • Support Portal
  • COMPANY
    • About us
    • Carreers
    • Partner
    • Contact us
    • Newsletter
  • RESOURCES
  • COMMUNITY
    • Open Source
    • Community Forum
    • Download
    • Documentation
    • Translate OTOBO
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu

SECURITY ADVISORY

OTOBO 10.0.17 – Security Patch

  • DESCRIPTION
  • MEASURES FOR SECURE OPERATION
  • BUG FIXES
  • DOWNLOADS
  • PUBLISHED:
  • RELEASE TYPE:
  • CRITICALITY:
  • AFFECTED VERSIONS:
  • REFERENCE:
  • December 20, 2022
  • Security Patch Release
  • MEDIUM
  • OTOBO 10.0
  • https://nvd.nist.gov/vuln/detail/CVE-2022-4427

Description

Problem

  • SQL Injection: We fixed a vulnerability that allowed attackers to inject SQL code through the “TicketSearch” web service operation.
  • JS Injection: We patched a vulnerability that enabled attackers with OTOBO admin rights to inject JS code.
  • Admin Interface: A code change prevents users with OTOBO admin rights from exploiting a vulnerability to inject code into ACLs.

Special thanks to Tim Püttmanns (maxence) for bringing these vulnerabilities to our attention.

Potential consequences

  • Direct execution of JS code after saving.

Measures for secure operations

Update to OTOBO 10.0.17

A security patch update is available to fix the vulnerability. Please update your system to ensure protection

➞ Download Security Patch Package

Bug Fixes

  • [Bugfix] Terminal notifications are now sent even when display is enabled for customers
  • [Bugfix] CLOB columns are now base64 decoded during migration from Oracle to MariaDB
  • Fixed Perl 5.34 shmwrite problem in OTOBO 10.0.x
  • [Tidied] Updated JavaScript libraries
  • Note: Manual changes to Loader::Agent::CommonJS###000-Framework and Loader::Customer::CommonJS###000-Framework (see below).
  • [Bugfix] Adapted S/MIME encryption to newer OpenSSL versions.
  • [Bugfix] Fixed a bug in the synchronization of LDAP groups to OTOBO roles

Notes on Changed SysConfig Options in OTOBO 10.0.17

JavaScript

As already done in OTOBO 10.1, the JavaScript libraries have now also been updated in OTOBO 10.0 with this patch. These are set in the SysConfig options “Loader::Agent::CommonJS###000-Framework” and “Loader::Customer::CommonJS###000-Framework”.

If these options were manually adjusted via SysConfig (which we advise against), an automatic update is not possible.
Please note the made adjustments in this case, reset the setting, perform the update, and adjust the option – if necessary – manually again afterwards.

Have a question? We’re here to help. Contact us.

Contact

As a support customer, you need assistance with the security patch. Please contact us through your access in the support portal.

Downloads

Security Patch Update

Download

Administrator manual

Download

Installation guideline

Download

Developer manual

Download
Search Search

Filter by

  • Add-On Feature
  • Article
  • Case Studies
  • News
  • Release Notes
  • Security Patch

Reset filter

Newsletter | Subscribe to receive news and updates from OTOBO

Company

About us
Careers
Job Opportunities
Become a Partner
Contact us
Newsletter

OTOBO | Simplify work and create exceptional service experiences.

The Source Code Owner and Maintainer of OTOBO.

Software

Service Management Platform
OTOBO Demo
OTOBO Download
OTOBO Documentation

Report a security issues:
security@otobo.org

Services

Support Portal
Consulting
Training
Support
Managed Services
Customizing
OTRS Migration
Find a Partner

Community

Open Source
Community Forum
Contribute
OTOBO Developer
OTOBO@GitHub

© 2026 Rother OSS GmbH | All rights reserved.
  • Cookie settings
  • Imprint
  • Privacy Policy
  • Disclaimer
Link to: OTOBO 10.1.6 Link to: OTOBO 10.1.6 OTOBO 10.1.6OTOBO Security Patch Link to: OTOBO 10.0.18 Link to: OTOBO 10.0.18 OTOBO Patch ReleaseOTOBO 10.0.18
Scroll to top Scroll to top Scroll to top