VendorsSmartBearzephyr_enterpriseany version
Vulnerabilities

SmartBear Zephyr Enterprise any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2023-22889
SmartBear Zephyr Enterprise through 7.15.0 mishandles user-defined input during report generation. This could lead to remote code execution by unauthenticated users.
Published 2023-03-08 · Modified
9.8EPSS 0.013
CVE-2023-22891
There exists a privilege escalation vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by authorized users to reset passwords for other accounts.
Published 2023-03-08 · Modified
8.1EPSS 0.005
CVE-2023-22890
SmartBear Zephyr Enterprise through 7.15.0 allows unauthenticated users to upload large files, which could exhaust the local drive space, causing a denial of service condition.
Published 2023-03-08 · Modified
7.5EPSS 0.006
CVE-2023-22892
There exists an information disclosure vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by unauthenticated users to read arbitrary files from Zephyr instances.
Published 2023-03-08 · Modified
7.5EPSS 0.006