The external frontend system uses numerous background calls to the backend. Each background request is treated as user activity so the SessionMaxIdleTime will not be reached. This issue affects: OTRS 7.0.x version 7.0.14 and prior versions.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1768
Reference (s):
- https://otrs.com/release-notes/otrs-security-advisory-2020-04/