CVE-2022-32739

EUVD-2022-35805
When Secure::DisableBanner system configuration has been disabled and agent shares his calendar via public URL, received ICS file contains OTRS release number.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.5 LOW
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
OTRSCNA
3.5 LOW
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 32%
Affected Products (NVD)
VendorProductVersion
otrscalendar_resource_planning
7.0.0 ≤
𝑥
< 7.0.31
otrscalendar_resource_planning
8.0.0 ≤
𝑥
< 8.0.23
otrsotrs
7.0.0 ≤
𝑥
< 7.0.35
otrsotrs
8.0.0 ≤
𝑥
< 8.0.23
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
otrs2
bionic
needs-triage
focal
needs-triage
impish
ignored
jammy
needs-triage
xenial
needs-triage