Vulnerability Description
There exists an information disclosure vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by unauthenticated users to read arbitrary files from Zephyr instances.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Smartbear | Zephyr Enterprise | <= 7.15 |
Related Weaknesses (CWE)
References
- https://smartbear.com/security/cve/Vendor Advisory
- https://smartbear.com/security/cve/Vendor Advisory
FAQ
What is CVE-2023-22892?
CVE-2023-22892 is a vulnerability with a CVSS score of 7.5 (HIGH). There exists an information disclosure vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by unauthenticated users to read arbitrary files from Zephyr instances.
How severe is CVE-2023-22892?
CVE-2023-22892 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-22892?
Check the references section above for vendor advisories and patch information. Affected products include: Smartbear Zephyr Enterprise.