EasyVista has been included in the 2026 Gartner® Magic Quadrant™ for ITSM!

EasyVista
EasyVista

EasyVista Group Vulnerability Disclosure Policy

We take the security of our products and services seriously, and we value the security community. The responsible disclosure of security vulnerabilities helps us protect our customers, users, and partners and contributes to the continuous improvement of the security of our products.

 

The Product Security Incident Response Team (PSIRT) of OTRS GmbH (subsidiary of EasyVista) is responsible for coordinating vulnerability management for the whole EasyVista Group.

The PSIRT of OTRS GmbH is also an officially recognized CVE Numbering Authority (CNA) and is responsible for coordinating the assignment and publication of CVE IDs for vulnerabilities within its CNA scope.

Guidelines

We require that all security researchers:

 

  • Respect the rules. Operate within the rules set forth by the PSIRT, or speak up if you strongly disagree with any of the rules.
  • Respect privacy. Make a good faith effort not to access, modify, disclose, or destroy another user’s data. Avoid degradation of user experience, disruption to production systems, and destruction or alteration of data.
  • Be patient. Make a good faith effort to clarify and support questions arising during the investigation. Keep information about any vulnerabilities you have discovered confidential between yourself and the PSIRT until the issue has been resolved and an appropriate security advisory or other public communication has been issued.
  • Do no harm. Act for the common good through the prompt and responsible reporting of vulnerabilities. Never intentionally exploit vulnerabilities beyond what is reasonably necessary to demonstrate their impact.
  • Use the designated communication channel. Report vulnerabilities through the communication channel specified below. Do not use personal email addresses, social media accounts, or other private channels to contact individual members of the security team regarding vulnerabilities or vulnerability management matters, unless explicitly instructed to do so.

If you follow these guidelines when reporting a security issue to us, we commit to:

 

  • Not pursue or support legal action against security researchers acting in good faith and in accordance with this policy.
  • Work with you to understand and resolve the reported issue as quickly as reasonably possible.
  • Provide an initial confirmation of receipt of your report within one week of submission.
  • Keep the information provided by security researchers confidential and use it only as required for investigation, remediation, coordinated disclosure, and applicable regulatory or legal obligations.
  • Recognize the contribution of the first reporter in the Security Researcher Hall of Fame, where appropriate, if the reported issue results in a security fix or configuration change. Researchers may use a pseudonym or remain anonymous.

Scope

This policy applies to products and services developed, maintained, or operated by companies within the EasyVista Group, including:

OTRS

  • OTRS and features developed and maintained by OTRS GmbH.
  • OTRS container distribution bundle, including container images customized, configured, or maintained by OTRS GmbH.
  • OTRS SaaS and platform components developed and operated by OTRS GmbH.
  • Security-relevant functionality and integrations developed and maintained by OTRS GmbH.

EasyVista

  • EV Service Manager
  • EV Service Apps
  • EV Self Help
  • EV Observe
  • EV Digital Experience Monitoring
  • EV Reach
  • EV Discovery

The scope includes security vulnerabilities affecting the products, their security-relevant components, and functionality developed and maintained by companies within the EasyVista Group.

Out of Scope

The following are explicitly excluded from the scope of this policy:

 

  • Vulnerabilities exclusively affecting third-party modules, extensions, integrations, base images, or components that have not been developed, customized, configured, or maintained by the EasyVista Group.
  • Any services hosted by third-party providers are excluded from scope.

 

Where a vulnerability affects a third-party component integrated into an EasyVista Group product, the EasyVista Group may coordinate with the relevant third-party maintainer or manufacturer as appropriate.

Supported Versions

OTRS

OTRS follows a rolling release model. Customers can upgrade to the latest available OTRS version at any time.

Security updates are provided for the current OTRS release as part of the rolling release lifecycle.

Older versions before OTRS 8.x, including ((OTRS)) Community Edition, are not supported and have known vulnerabilities.

EasyVista

The official support period for EasyVista software versions is 24 months after their public availability.

The applicable public availability date and version history can be found in the EasyVista version history:
https://docs.easyvista.com/docs/version-history

Older versions outside of the 24-month support period are not supported and may have known vulnerabilities.

Customers using unsupported versions are encouraged to upgrade to a currently supported version.

Vulnerability Management, Coordinated Disclosure and Cyber Resilience Act

The EasyVista Group maintains a coordinated vulnerability management and disclosure process covering vulnerabilities reported by external security researchers, customers, partners, suppliers, internal security teams, and other relevant sources.

These processes are designed to support compliance with applicable cybersecurity and product security requirements, including Regulation (EU) 2024/2847, the Cyber Resilience Act (CRA), where applicable.

The PSIRT of OTRS GmbH acts as the central vulnerability management function for the EasyVista Group and coordinates the handling of reported vulnerabilities across the relevant EasyVista Group entities and product teams. As an officially recognized CVE Numbering Authority (CNA), the OTRS GmbH PSIRT may assign CVE identifiers to vulnerabilities within its CNA scope in accordance with the applicable CVE Program policies and procedures.

Depending on the affected product or service the PSIRT works together with the responsible product engineering, development, operations, and security teams to:

  • receive, document, and track vulnerability reports from internal and external sources
  • validate and reproduce reported vulnerabilities
  • assess their security impact, severity, and potential effect on affected products
  • identify affected products, components and supported versions
  • coordinate remediation and mitigation measures throughout the applicable support period
  • coordinate security updates and other corrective or mitigating measures
  • coordinate vulnerability information with relevant third-party component maintainers where required
  • support the identification and handling of actively exploited vulnerabilities
  • assign CVE numbers and publication where applicable
  • coordinate disclosure with affected parties and external security researchers
  • maintain appropriate vulnerability and security documentation
  • track vulnerabilities throughout their lifecycle
  • prepare security advisories and other relevant security communications
  • support communication with affected users regarding vulnerabilities, incidents, mitigations, and corrective measures where required
  • support the preparation and coordination of regulatory notifications concerning actively exploited vulnerabilities and severe security incidents where applicable

Where a vulnerability affects a third-party component, base image, module or integration used within an EasyVista Group product, the PSIRT may coordinate the disclosure and remediation process with the respective third-party maintainer or manufacturer. This does not extend the scope of this policy to vulnerabilities exclusively affecting third-party components that have not been developed, customized, configured, or maintained by the EasyVista Group.

The legal responsibility for fulfilling applicable obligations under the CRA remains with the respective legal entity acting as the manufacturer of the affected product. The PSIRT of OTRS GmbH provides the central operational coordination and vulnerability management function for the EasyVista Group and supports the responsible entities and product teams in fulfilling their applicable vulnerability-handling obligations.

Where an actively exploited vulnerability or a severe security incident falls within the applicable CRA reporting obligations, the PSIRT coordinates the internal response and supports the responsible manufacturer in preparing and submitting the required notifications through the applicable reporting mechanisms.

How to Report a Security Vulnerability

If you believe you have found a security vulnerability in one of our products or services, please report it to us by emailing:

Please include the following information with your report:

 

  • A description of the location and potential impact of the vulnerability
  • The affected product, service, component, or version, if known
  • A detailed description of the steps required to reproduce the vulnerability
  • Proof-of-concept code, scripts, screenshots, logs, or other technical information that may help us reproduce and understand the issue
  • Information about any known exploitation or evidence that the vulnerability may already be actively exploited
  • Your name or pseudonym for recognition in our Security Researcher Hall of Fame. If you prefer to remain anonymous, you may submit your report under a pseudonym

Please do not include unnecessary personal data or customer data in your report.

 

If you would like to encrypt sensitive information, please use our published PGP key: 2048R/9C227C6B
GPG Fingerprint: E330 4608 DA6E 34B7 1551 C244 7F9E 44E9 9C22 7C6B

Disclosure and Security Advisories

We aim to resolve validated vulnerabilities within a reasonable timeframe based on their severity, exploitability, affected products, and technical complexity.

 

Information about vulnerabilities will generally remain confidential between the reporter and the EasyVista Group until an appropriate remediation or mitigation is available.

 

Where appropriate, resolved vulnerabilities may be published through security advisories or other security communications. The timing and content of public disclosure may depend on the severity of the vulnerability, the availability of remediation, coordinated disclosure arrangements, exploitation status, regulatory requirements, and other relevant circumstances.

Where a CVE identifier is assigned, the vulnerability may be published through the applicable CVE and security advisory channels in accordance with the policies of the CVE Program.

The EasyVista Group reserves the right to modify disclosure timelines where necessary to protect customers, users, or the broader security community.

Security Researcher Hall of Fame

We appreciate the work of security researchers who responsibly report vulnerabilities to us.

 

Where a valid vulnerability results in a security fix or configuration change, we may recognize the first reporter in our Security Researcher Hall of Fame, unless the researcher prefers to remain anonymous or uses a pseudonym.

 

Recognition does not imply that the EasyVista Group endorses or assumes responsibility for any activity beyond the responsible disclosure of the reported vulnerability.

Changes to this Policy

This Vulnerability Disclosure Policy may be updated from time to time to reflect changes in our products, services, organizational structure, vulnerability management processes, CNA scope, or applicable legal and regulatory requirements.

 

The current version of this policy will be made publicly available through the EasyVista Group’s designated security and vulnerability disclosure channels.