First published: Wed Mar 08 2023(Updated: )
SmartBear Zephyr Enterprise through 7.15.0 mishandles user-defined input during report generation. This could lead to remote code execution by unauthenticated users.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SmartBear Zephyr Enterprise | <=7.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for SmartBear Zephyr Enterprise is CVE-2023-22889.
The severity of CVE-2023-22889 is critical with a score of 9.8.
SmartBear Zephyr Enterprise versions up to and including 7.15.0 are affected by CVE-2023-22889.
CVE-2023-22889 can be exploited by unauthenticated users to execute remote code.
To fix CVE-2023-22889, it is recommended to update SmartBear Zephyr Enterprise to version 7.15.1 or later.