CVE-2022-46901: Vocera Report Server
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is an Access Control Violation for Database Operations. The Vocera Report Console contains a websocket interface that allows for the unauthenticated execution of various tasks and database functions. This includes system tasks, and backing up, loading, and clearing of the database.
Affected products
- Vocera Report Server: from 5.0.0, up to and including 5.8.0.135
- Vocera Voice Server: from 5.0.0, up to and including 5.8.0.135
Published 2023-07-25. Last modified 2026-06-17.