First published: Wed Mar 08 2023(Updated: )
There exists an information disclosure vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by unauthenticated users to read arbitrary files from Zephyr instances.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SmartBear Zephyr Enterprise | <=7.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-22892 is high with a severity value of 7.5.
Unauthenticated users can exploit CVE-2023-22892 to read arbitrary files from Zephyr instances.
SmartBear Zephyr Enterprise versions up to and including 7.15.0 are affected by CVE-2023-22892.
No, authentication is not required to exploit CVE-2023-22892.
You can find more information about CVE-2023-22892 on the SmartBear website: https://smartbear.com/security/cve/