« Volver al listado

CVE-2022-32740

Estado: ModificadaMedia (5.3)—

A reply to a forwarded email article by a 3rd party could unintensionally expose the email content to the ticket customer under certain circumstances.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-32740",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@otrs.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 3.5,
          "attackVector": "NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.1
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@otrs.com",
      "affectedData": [
        {
          "vendor": "OTRS AG",
          "product": "OTRS",
          "versions": [
            {
              "status": "affected",
              "version": "7.0.x",
              "versionType": "custom",
              "lessThanOrEqual": "7.0.34"
            },
            {
              "status": "affected",
              "version": "8.0.x",
              "versionType": "custom",
              "lessThanOrEqual": "8.0.22"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-06-13T08:15:19.030",
  "references": [
    {
      "url": "https://otrs.com/release-notes/otrs-security-advisory-2022-08/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@otrs.com"
    },
    {
      "url": "https://otrs.com/release-notes/otrs-security-advisory-2022-08/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@otrs.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A reply to a forwarded email article by a 3rd party could unintensionally expose the email content to the ticket customer under certain circumstances."
    },
    {
      "lang": "es",
      "value": "Una respuesta a un artículo de correo electrónico reenviado por un tercero podría exponer involuntariamente el contenido del correo electrónico al cliente del ticket bajo determinadas circunstancias"
    }
  ],
  "lastModified": "2026-06-17T04:47:50.090",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:otrs:otrs:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7CC37884-BF0A-4F67-AFC3-1C95BE001A55",
              "versionEndExcluding": "7.0.35",
              "versionStartIncluding": "7.0.0"
            },
            {
              "criteria": "cpe:2.3:a:otrs:otrs:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "01314391-90B9-4D17-9571-7EE08FEF0D5C",
              "versionEndExcluding": "8.0.23",
              "versionStartIncluding": "8.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@otrs.com"
}