Vulnerabilities > CVE-2022-46901 - Exposure of Resource to Wrong Sphere vulnerability in Vocera Report Server and Voice Server

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
vocera
CWE-668

Summary

An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is an Access Control Violation for Database Operations. The Vocera Report Console contains a websocket interface that allows for the unauthenticated execution of various tasks and database functions. This includes system tasks, and backing up, loading, and clearing of the database.

Vulnerable Configurations

Part Description Count
Application
Vocera
2

Common Weakness Enumeration (CWE)