Vulnerability Description
SmartBear Zephyr Enterprise through 7.15.0 mishandles user-defined input during report generation. This could lead to remote code execution by unauthenticated users.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Smartbear | Zephyr Enterprise | <= 7.15 |
Related Weaknesses (CWE)
References
- https://smartbear.com/security/cve/Vendor Advisory
- https://smartbear.com/security/cve/Vendor Advisory
FAQ
What is CVE-2023-22889?
CVE-2023-22889 is a vulnerability with a CVSS score of 9.8 (CRITICAL). SmartBear Zephyr Enterprise through 7.15.0 mishandles user-defined input during report generation. This could lead to remote code execution by unauthenticated users.
How severe is CVE-2023-22889?
CVE-2023-22889 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-22889?
Check the references section above for vendor advisories and patch information. Affected products include: Smartbear Zephyr Enterprise.