CVE-2019-9621
גבוהה 7.5 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x before 8.8.11 patch 3 allows SSRF via the ProxyServlet component.
מדדים
- CVSS 3.1
-
7.5 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - EPSS — סבירות ניצול
- 81% (אחוזון 100) נכון ל-30/7/2026
- CWE
- CWE-918
מוצרים מושפעים
synacor: zimbra collaboration suite
קישורים
- https://blog.zimbra.com/2019/03/9826/ Vendor Advisory
- https://wiki.zimbra.com/wiki/Security_Center Release NotesVendor Advisory
- https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories Vendor Advisory
- https://blog.zimbra.com/2019/03/9826/ Vendor Advisory
- https://wiki.zimbra.com/wiki/Security_Center Release NotesVendor Advisory
- https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories Vendor Advisory
- http://packetstormsecurity.com/files/152487/Zimbra-Collaboration-Autodiscover-… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/153190/Zimbra-XML-Injection-Server-Side-R… ExploitThird Party AdvisoryVDB Entry
- http://www.rapid7.com/db/modules/exploit/linux/http/zimbra_xxe_rce ExploitThird Party Advisory
- https://www.exploit-db.com/exploits/46693/ ExploitThird Party AdvisoryVDB Entry