---
title: "CVE-2018-7567\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2018-7567?format=md
keywords: index, follow
---

# CVE-2018-7567

Publication date 4 March 2018

Last updated 6 August 2026

---

Ubuntu priority

**High**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**7.2 · High**

[Score breakdown](https://ubuntu.com/security/CVE-2018-7567?format=md#impact-score)

Toggle side navigation

## Description

In the Admin Package Manager in Open Ticket Request System (OTRS) 5.0.0
through 5.0.24 and 6.0.0 through 6.0.1, authenticated admins are able to
exploit a Blind Remote Code Execution vulnerability by loading a crafted
opm file with an embedded CodeInstall element to execute a command on the
server during package installation. NOTE: the vendor disputes this issue
stating "the behaviour is as designed and needed for different packages to
be installed", "there is a security warning if the package is not verified
by OTRS Group", and "there is the possibility and responsibility of an
admin to check packages before installation which is possible as they are
not binary.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2018-7567?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| otrs2 | 19.10 eoan | Not affected |
| 19.04 disco | Not affected |
| 18.10 cosmic | Not affected |
| 18.04 LTS bionic | Not affected |
| 17.10 artful | Not affected |
| 16.04 LTS xenial | Not affected |
| 14.04 LTS trusty | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [msalvatore](https://launchpad.net/~msalvatore)

Vendor states that everything is functioning as designed.
Marking as not-affected as this CVE is disputed.

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

7.2 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | High |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | High |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 7.2 · High |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7567)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2018-7567)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2018-7567)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2018-7567)

### Other references

* <https://0day.today/exploit/29938>
* <https://www.cve.org/CVERecord?id=CVE-2018-7567>
