CVE-2022-32739

OTRS version number is always in the exported ICS files

Description

When Secure::DisableBanner system configuration has been disabled and agent shares his calendar via public URL, received ICS file contains OTRS release number.

Remediation

Solution:

  • Update to OTRS 8.0.23 or OTRS 7.0.35. Update to OTRSCalendarResourcePlanning 8.0.23 or OTRSCalendarResourcePlanning 7.0.31.

Category

3.5
CVSS
Severity: Low
CVSS 3.1 •
CVSS 2.0 •
EPSS 0.29%
Vendor Advisory otrs.com
Affected: OTRS AG OTRS
Affected: OTRS AG OTRSCalendarResourcePlanning
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2022-32739?
CVE-2022-32739 has been scored as a low severity vulnerability.
How to fix CVE-2022-32739?
To fix CVE-2022-32739: Update to OTRS 8.0.23 or OTRS 7.0.35. Update to OTRSCalendarResourcePlanning 8.0.23 or OTRSCalendarResourcePlanning 7.0.31.
Is CVE-2022-32739 being actively exploited in the wild?
As for now, there are no information to confirm that CVE-2022-32739 is being actively exploited. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2022-32739?
CVE-2022-32739 affects OTRS AG OTRS, OTRS AG OTRSCalendarResourcePlanning.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.