CVE-2023-22892

HIGH

Smartbear Zephyr Enterprise < 7.15 - Exposure to Wrong Actor

Title source: rule

Description

There exists an information disclosure vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by unauthenticated users to read arbitrary files from Zephyr instances.

Scores

CVSS v3 7.5
EPSS 0.0043
EPSS Percentile 62.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-668
Status published

Affected Products (1)

smartbear/zephyr_enterprise < 7.15

Timeline

Published Mar 08, 2023
Tracked Since Feb 18, 2026