CVE-2022-46900: Vocera Report Server
Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.
An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is Path Traversal in the Task Exec filename. The Vocera Report Console contains various jobs that are executed on the server at specified intervals, e.g., backup, etc. An authenticated user has the ability to modify these entries and set the executable path and parameters.
Affected products
- Vocera Report Server: from 5.0.0, up to and including 5.8.0.135
- Vocera Voice Server: from 5.0.0, up to and including 5.8.0.135
Published 2023-07-25. Last modified 2026-06-17.