CVE-2020-35123
Summary
| CVE | CVE-2020-35123 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-12-17 04:15:00 UTC |
| Updated | 2020-12-22 17:26:00 UTC |
| Description | In Zimbra Collaboration Suite Network Edition versions < 9.0.0 P10 and 8.8.15 P17, there exists an XXE vulnerability in the saml consumer store extension, which is vulnerable to XXE attacks. This has been fixed in Zimbra Collaboration Suite Network edition 9.0.0 Patch 10 and 8.8.15 Patch 17. |
Risk And Classification
Problem Types: CWE-611
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Zimbra | Collaboration | All | All | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | - | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p1 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p10 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p11 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p12 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p13 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p14 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p15 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p16 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p2 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p3 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p4 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p5 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p6 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p7 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p8 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p9 | All | All |
| Application | Zimbra | Collaboration | 9.0.0 | - | All | All |
| Application | Zimbra | Collaboration | 9.0.0 | p1 | All | All |
| Application | Zimbra | Collaboration | 9.0.0 | p2 | All | All |
| Application | Zimbra | Collaboration | 9.0.0 | p3 | All | All |
| Application | Zimbra | Collaboration | 9.0.0 | p4 | All | All |
| Application | Zimbra | Collaboration | 9.0.0 | p5 | All | All |
| Application | Zimbra | Collaboration | 9.0.0 | p6 | All | All |
| Application | Zimbra | Collaboration | 9.0.0 | p7 | All | All |
| Application | Zimbra | Collaboration | 9.0.0 | p8 | All | All |
| Application | Zimbra | Collaboration | 9.0.0 | p9 | All | All |
| Application | Zimbra | Collaboration | All | All | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | - | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p1 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p10 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p11 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p12 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p13 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p14 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p15 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p16 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p2 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p3 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p4 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p5 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p6 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p7 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p8 | All | All |
| Application | Zimbra | Collaboration | 8.8.15 | p9 | All | All |
| Application | Zimbra | Collaboration | 9.0.0 | - | All | All |
| Application | Zimbra | Collaboration | 9.0.0 | p1 | All | All |
| Application | Zimbra | Collaboration | 9.0.0 | p2 | All | All |
| Application | Zimbra | Collaboration | 9.0.0 | p3 | All | All |
| Application | Zimbra | Collaboration | 9.0.0 | p4 | All | All |
| Application | Zimbra | Collaboration | 9.0.0 | p5 | All | All |
| Application | Zimbra | Collaboration | 9.0.0 | p6 | All | All |
| Application | Zimbra | Collaboration | 9.0.0 | p7 | All | All |
| Application | Zimbra | Collaboration | 9.0.0 | p8 | All | All |
| Application | Zimbra | Collaboration | 9.0.0 | p9 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Zimbra Releases/9.0.0/P10 - Zimbra :: Tech Center | CONFIRM | wiki.zimbra.com | Third Party Advisory, Vendor Advisory |
| wiki.zimbra.com/wiki/Security_Center | CONFIRM | wiki.zimbra.com | Product |
| wiki.zimbra.com/wiki/Zimbra_Security_Advisories | CONFIRM | wiki.zimbra.com | Vendor Advisory |
| Zimbra Releases/8.8.15/P17 - Zimbra :: Tech Center | CONFIRM | wiki.zimbra.com | Release Notes, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.