CVE-2023-22889: Code Injection
Published Mar 8, 2023
·Updated
SmartBear Zephyr Enterprise through 7.15.0 mishandles user-defined input during report generation. This could lead to remote code execution by unauthenticated users.
Affected Software
1 affected component
SMARTBEAR Zephyr Enterprise<=7.15
Event History
Mar 8, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for SmartBear Zephyr Enterprise?
The vulnerability ID for SmartBear Zephyr Enterprise is CVE-2023-22889.
2
What is the severity of CVE-2023-22889?
The severity of CVE-2023-22889 is critical with a score of 9.8.
3
What is affected by CVE-2023-22889?
SmartBear Zephyr Enterprise versions up to and including 7.15.0 are affected by CVE-2023-22889.
4
How can CVE-2023-22889 be exploited?
CVE-2023-22889 can be exploited by unauthenticated users to execute remote code.
5
How can I fix CVE-2023-22889?
To fix CVE-2023-22889, it is recommended to update SmartBear Zephyr Enterprise to version 7.15.1 or later.