CVE-2023-22890: Smartbear Zephyr Enterprise

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

SmartBear Zephyr Enterprise through 7.15.0 allows unauthenticated users to upload large files, which could exhaust the local drive space, causing a denial of service condition.

Affected products

  • Smartbear Zephyr Enterprise: up to and including 7.15

Published 2023-03-08. Last modified 2026-06-17.